Junglewise Threat Intelligence

CVE-2026-9039: XCharge C6 insecure default credentials in remote management service

CVE-2026-9039 · Severity: info · CVSS 7.6 · Published 2026-05-28

Technologies: XCharge C6. Vendors: XCharge.

Executive brief

The XCharge C6 electric vehicle charging station contains a security flaw where its management interface is accessible through the physical charging cable. An attacker with physical access to the charger could use a malicious device to log in using default administrative credentials. This would allow the attacker to take full control of the charging station, potentially disrupting service or modifying device settings.

Technical details

A configuration weakness (CWE-1188) in the XCharge C6 remote management service allows an authenticated session to be established over the Power Line Communication (PLC) or signaling channel intended for vehicle-to-charger communication. The service is improperly exposed on the physical charging interface and utilizes a default administrative credential. An attacker can connect a malicious device to the charging connector to access the management interface and gain full administrative rights. XCharge has reportedly deployed a firmware update to address this issue as of May 22, 2026.

Affected products

  • XCharge C6 < May_22_2026

Timeline

  • 2026-05-22: patched: XCharge confirmed update deployment for all affected chargers.
  • 2026-05-28: advisory: CISA and NVD published advisory details.

References

Related threats