No advisories yet.
Solution
XCharge has confirmed that the update has been deployed for all affected chargers. Users with questions can reach out to XCharge Support for further details if needed. https://www.xcharge.com/contact
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xcharge
Xcharge c6 |
|
| Vendors & Products |
Xcharge
Xcharge c6 |
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access. | |
| Title | Initialization of a resource with an insecure default in XCharge C6 | |
| Weaknesses | CWE-1188 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-05-29T15:01:35.931Z
Reserved: 2026-05-19T16:54:40.242Z
Link: CVE-2026-9039
Updated: 2026-05-29T15:01:30.772Z
Status : Awaiting Analysis
Published: 2026-05-28T20:16:27.350
Modified: 2026-05-29T15:42:56.873
Link: CVE-2026-9039
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:47:55Z