Charging Controllers Accept Trusted Code From the Wrong Place

XCharge C6 units can be turned into high-privilege footholds because the controller trusts firmware and service channels it should not trust. One flaw lets a management-path update install unauthorized code, another can expose admin access over charger signaling, and a third lets physical access to the charging interface trigger memory corruption with elevated privileges. CISA says the issue affects XCharge C6 charging controllers used in transportation systems worldwide. XCharge says the update has been deployed for all affected chargers, and the advisory points to firmware authenticity failure, stack-based buffer overflow, and a default-credential management path as the three CVEs involved. The practical lesson is that charging gear can no longer be treated as a dumb peripheral. Its own management and connector interfaces can become the entry point for persistent compromise, even when the surrounding network is segmented.

Part of the PlainSec briefing for 2026-05-28

Sources