No advisories yet.
Solution
XCharge has confirmed that the update has been deployed for all affected chargers. Users with questions can reach out to XCharge Support for further details if needed. https://www.xcharge.com/contact
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xcharge
Xcharge c6 |
|
| Vendors & Products |
Xcharge
Xcharge c6 |
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed expected bounds. Because the input is not sufficiently validated, memory corruption may occur, which can lead to execution of unauthorized code with elevated privileges. | |
| Title | Stack-based buffer overflow in XCharge C6 | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-29T15:00:43.770Z
Reserved: 2026-05-19T16:54:39.327Z
Link: CVE-2026-9038
Updated: 2026-05-29T15:00:38.156Z
Status : Awaiting Analysis
Published: 2026-05-28T20:16:27.227
Modified: 2026-05-29T15:42:56.873
Link: CVE-2026-9038
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:47:57Z