VORANT. Threat Intelligence Sign in Get the full feed

XCharge C6 electric vehicle chargers contain three critical vulnerabilities enabling…

high vulnerability transportation

XCharge C6 electric vehicle chargers contain three critical vulnerabilities enabling firmware tampering, code execution via buffer overflow, and administrative access via default credentials.

CISA has disclosed three vulnerabilities in XCharge C6 electric vehicle charging controllers deployed worldwide in the transportation sector. CVE-2026-9037 involves a firmware update mechanism that fails to validate cryptographic signatures, allowing attackers who can intercept or impersonate the management channel to install malicious firmware. CVE-2026-9038 is a stack-based buffer overflow in signal-processing logic that permits physical attackers at the charging interface to trigger memory corruption and execute unauthorized code with elevated privileges. CVE-2026-9039 exposes a remote management service on the charging connector interface that accepts default administrative credentials, enabling physical attackers to gain full administrative control.

All three vulnerabilities affect XCharge C6 devices with firmware versions prior to May 22, 2026. XCharge has confirmed that remediation updates have been deployed to all affected chargers. The vendor recommends users contact XCharge Support if they have questions about the remediation status of their devices. No known public exploitation targeting these vulnerabilities has been reported to CISA at this time.

Mentioned in this report

Vulnerabilities CVE-2026-9037CVE-2026-9038CVE-2026-9039

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-08

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free