IM
IronMonkey Threat Research
‹ Back to ICS Advisories

XCharge C6

CRITICAL
CVSS 9.8
Date 2026-05-28T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to gain administrator rights or execute code on the affected device.

// Vulnerabilities (3)

CVE ID CVSS Score Severity Description
CVE-2026-9039 7.6 high
A configuration weakness in the device's remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.
CVE-2026-9038 7.6 high
A stack-based buffer overflow vulnerability in the charging controller's signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges.
CVE-2026-9037 9.8 critical
A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device,

// Remediations (1)

Mitigation: XCharge has confirmed that the update has been deployed for all affected chargers. Users with questi
XCharge has confirmed that the update has been deployed for all affected chargers. Users with questions can reach out to XCharge Support for further details if needed. https://www.xcharge.com/contact

// References