CVE-2026-77974EPSS p16.7%

CVE-2026-77974CVE-2026-77974

Description

After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.

Scoring

CVSS 8.0 ()
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.27% probability of exploitation · percentile 16.7% · 2026-10-05T12:00:23Z
Last modified2026-09-10
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.