Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 16, 2026
Missing firmware validation allows remote code execution
CVE-2026-22097
Description
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.
Patches
Vulnerability mechanics
References
1- csirt.divd.nl/DIVD-2026-00001/mitrethird-party-advisory
News mentions
0No linked articles in our index yet.