CVE-2026-9039
Description
A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Default administrative credentials in XCharge C6's remote management service allow a physically connected malicious charging device to gain full administrative access.
Vulnerability
The remote management service of XCharge C6 (versions prior to May 22, 2026) contains a configuration weakness that permits an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling [1]. The service is accessible on interfaces exposed through the charging connector and accepts a default administrative credential [1]. This allows an attacker with physical access to the charging interface to authenticate as an administrator.
Exploitation
An attacker must have physical access to the charging connector of an affected XCharge C6 device. By connecting a malicious charging device or a device that can communicate over the charging interface, the attacker can establish a session on the remote management service using the known default administrative credential [1]. No additional authentication bypass or user interaction is required.
Impact
Successful exploitation grants the attacker full administrative access to the XCharge C6 device. This can result in complete compromise of the device, including the ability to modify configuration, install unauthorized firmware, and disrupt charging operations [1]. The attacker gains high privileges on the device.
Mitigation
XCharge has released a firmware update on May 22, 2026 that addresses this vulnerability [1]. Users are advised to update affected XCharge C6 devices to the latest firmware version available after May 22, 2026. No workarounds are documented in the advisory; applying the patch is the recommended mitigation.
AI Insight generated on May 28, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- XCharge C6CISA ICS Advisories