top of page
perceptive_background_267k.jpg

XCharge C6

Published:

28 mei 2026 om 12:00:00

Alert date:

28 mei 2026 om 17:06:19

Source:

cisa.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure

CISA published an advisory for multiple critical vulnerabilities in XCharge C6 electric vehicle charging controllers. The vulnerabilities include a firmware update mechanism that fails to validate authenticity (CVE-2026-9037, CVSS 9.8), a stack-based buffer overflow in signal processing (CVE-2026-9038, CVSS 7.6), and insecure default credentials in the remote management service (CVE-2026-9039, CVSS 7.6). Successful exploitation could allow attackers to gain administrator rights or execute code on affected devices. The vulnerabilities affect XCharge C6 chargers deployed worldwide in transportation systems critical infrastructure. XCharge has confirmed updates have been deployed for all affected chargers.

Technical details

Mitigation steps:

Affected products:

XCharge C6

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page