Executive brief
XCharge C6 electric vehicle charging stations are affected by a memory vulnerability in their signal-processing logic. An attacker with physical access to the charging connector can send specially crafted messages to crash the controller or take control of the device. This could lead to unauthorized access to the charger's internal systems, potentially disrupting charging services or compromising the local station's security.
Technical details
A stack-based buffer overflow (CWE-121) exists in the signal-processing logic of the XCharge C6 charging controller. The vulnerability is triggered when the device receives message fields through the physical charging interface that exceed expected bounds due to insufficient input validation. An attacker with physical access to the charging connector can exploit this to cause memory corruption, potentially leading to arbitrary code execution with elevated privileges. XCharge has reportedly deployed a firmware update to address this issue in all affected chargers as of May 22, 2026.
Affected products
- XCharge C6 Versions prior to May 22, 2026
Timeline
- 2026-05-22: patched: Firmware update deployed to affected chargers.
- 2026-05-28: advisory: CISA and NVD published advisory details.