A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.

Project Subscriptions

Vendors Products
Xcharge Subscribe
Advisories

No advisories yet.

Fixes

Solution

XCharge has confirmed that the update has been deployed for all affected chargers. Users with questions can reach out to XCharge Support for further details if needed. https://www.xcharge.com/contact


Workaround

No workaround given by the vendor.

History

Fri, 29 May 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Xcharge
Xcharge c6
Vendors & Products Xcharge
Xcharge c6

Fri, 29 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.
Title Download of code without integrity check in XCharge C6
Weaknesses CWE-494
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-05-29T15:00:12.905Z

Reserved: 2026-05-19T16:54:38.351Z

Link: CVE-2026-9037

cve-icon Vulnrichment

Updated: 2026-05-29T14:59:56.852Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-28T20:16:27.093

Modified: 2026-05-29T15:42:56.873

Link: CVE-2026-9037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:47:58Z

Weaknesses