The Cybersecurity and Infrastructure Security Agency issued an advisory warning that XCharge C6 electric vehicle charging controllers contain three security flaws, including one rated critical with a CVSS score of 9.8.
The most severe vulnerability, tracked as CVE-2026-9037, involves a missing firmware validation mechanism that allows attackers to execute arbitrary code on the device by connecting a malicious unit through the charging port. The flaw stems from the controller’s failure to cryptographically verify update packages before installation.
CVE-2026-9038 describes a stack-based buffer overflow in the device’s SLAC protocol handling, a communication standard used in vehicle-to-grid connections. An attacker physically connected to the charger can trigger memory corruption that leads to remote code execution. Research demonstrated that any EV charger using Qualcomm’s open-plc-utils library could be vulnerable to related issues.
The third vulnerability, CVE-2026-9039, exposes a configuration weakness in the remote management service that allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service accepts default administrative credentials accessible through interfaces exposed via the charging connector.
CISA rated the first two vulnerabilities as critical and the third as high severity. The devices are deployed in transportation environments worldwide, and while no public exploitation has been reported yet, experts warn that the physical accessibility of charging stations makes them attractive targets for attackers seeking grid-level disruption.
XCharge has not released a coordinated patch timeline. CISA recommends that operators isolate the charging controllers from corporate networks and restrict physical access to authorized personnel only.