Vulnerabilities · 109 days ago

Charging Controllers Accept Trusted Code From the Wrong Place

XCharge C6 units can be turned into high-privilege footholds because the controller trusts firmware and service channels it should not trust. One flaw lets a management-path update install unauthorized code, another can expose admin access over charger signaling, and a third lets physical access to the charging interface trigger memory corruption with elevated privileges.

CISA says the issue affects XCharge C6 charging controllers used in transportation systems worldwide. XCharge says the update has been deployed for all affected chargers, and the advisory points to firmware authenticity failure, stack-based buffer overflow, and a default-credential management path as the three CVEs involved.

The practical lesson is that charging gear can no longer be treated as a dumb peripheral. Its own management and connector interfaces can become the entry point for persistent compromise, even when the surrounding network is segmented.

CVE-2026-9037

NVD KEV

CVE-2026-9038

NVD KEV

CVE-2026-9039

NVD KEV

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-28

Editions

Related stories