Executive brief
The XCharge C6 electric vehicle charging controller contains a flaw in how it handles software updates. An attacker can trick the device into installing malicious software because the system does not verify if the update is authentic. This could allow a remote attacker to take full control of the charging station, potentially leading to service disruptions or unauthorized access to the device's functions.
Technical details
The vulnerability is classified as a 'Download of Code Without Integrity Check' (CWE-494) within the firmware update mechanism of the XCharge C6 charging controller. The device's management interface does not verify cryptographic signatures of incoming firmware packages. An attacker capable of intercepting or impersonating the management channel can deliver a malicious firmware image. Successful exploitation results in the execution of unauthorized code with administrative privileges. XCharge has reportedly deployed an update to all affected chargers as of May 22, 2026.
Affected products
- XCharge C6 < May_22_2026
CVE identifiers
- CVE-2026-9039
- CVE-2026-9037
- CVE-2026-9038
Timeline
- 2026-05-22: patched: XCharge confirmed updates were deployed to affected chargers.
- 2026-05-28: disclosed: Initial publication of ICS Advisory ICSA-26-148-08.