VYPR
High severityNVD Advisory· Published May 28, 2026

CVE-2026-9039

CVE-2026-9039

Description

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Default administrative credentials in XCharge C6's remote management service allow a physically connected malicious charging device to gain full administrative access.

Vulnerability

The remote management service of XCharge C6 (versions prior to May 22, 2026) contains a configuration weakness that permits an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling [1]. The service is accessible on interfaces exposed through the charging connector and accepts a default administrative credential [1]. This allows an attacker with physical access to the charging interface to authenticate as an administrator.

Exploitation

An attacker must have physical access to the charging connector of an affected XCharge C6 device. By connecting a malicious charging device or a device that can communicate over the charging interface, the attacker can establish a session on the remote management service using the known default administrative credential [1]. No additional authentication bypass or user interaction is required.

Impact

Successful exploitation grants the attacker full administrative access to the XCharge C6 device. This can result in complete compromise of the device, including the ability to modify configuration, install unauthorized firmware, and disrupt charging operations [1]. The attacker gains high privileges on the device.

Mitigation

XCharge has released a firmware update on May 22, 2026 that addresses this vulnerability [1]. Users are advised to update affected XCharge C6 devices to the latest firmware version available after May 22, 2026. No workarounds are documented in the advisory; applying the patch is the recommended mitigation.

AI Insight generated on May 28, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1