# XCharge C6 electric vehicle chargers contain three critical vulnerabilities enabling…

Published: 2026-05-28 · Severity: high · Sectors: transportation
Canonical: https://vorant.io/reports/e7e204b1-e207-49d0-9b92-bda87d7f5083/xcharge-c6-electric-vehicle-chargers-contain-three-critical-vulnerabilities

> XCharge C6 electric vehicle chargers contain three critical vulnerabilities enabling firmware tampering, code execution via buffer overflow, and administrative access via default credentials.

CISA has disclosed three vulnerabilities in XCharge C6 electric vehicle charging controllers deployed worldwide in the transportation sector. CVE-2026-9037 involves a firmware update mechanism that fails to validate cryptographic signatures, allowing attackers who can intercept or impersonate the management channel to install malicious firmware. CVE-2026-9038 is a stack-based buffer overflow in signal-processing logic that permits physical attackers at the charging interface to trigger memory corruption and execute unauthorized code with elevated privileges. CVE-2026-9039 exposes a remote management service on the charging connector interface that accepts default administrative credentials, enabling physical attackers to gain full administrative control.

All three vulnerabilities affect XCharge C6 devices with firmware versions prior to May 22, 2026. XCharge has confirmed that remediation updates have been deployed to all affected chargers. The vendor recommends users contact XCharge Support if they have questions about the remediation status of their devices. No known public exploitation targeting these vulnerabilities has been reported to CISA at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9037, CVE-2026-9038, CVE-2026-9039

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-08

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e7e204b1-e207-49d0-9b92-bda87d7f5083/xcharge-c6-electric-vehicle-chargers-contain-three-critical-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
