news.mlab.sh
Back to the feed
threat-intel

XCharge C6

Critical
Summary

This CISA advisory details a critical vulnerability series affecting XCharge C6 charging controllers worldwide. The vulnerabilities include a firmware validation flaw, a stack-based buffer overflow, and a misconfigured remote management service, all allowing an attacker with physical access to potentially gain administrator rights and execute arbitrary code. XCharge has deployed an update to address these issues, but immediate mitigation steps are recommended to minimize the risk of exploitation.

The XCharge C6 charging controller has been identified with multiple vulnerabilities that could allow unauthorized access and control. Specifically, the device’s firmware update mechanism lacks proper authentication, enabling an attacker to install malicious firmware via the management interface. Simultaneously, a stack-based buffer overflow vulnerability exists within the charging controller’s signal processing logic, exploitable through physical access to the charging interface. Finally, a misconfiguration in the device’s remote management service exposes an administrative credential, granting an attacker full control upon connection. These vulnerabilities pose a significant risk to critical infrastructure, particularly transportation systems, given the widespread deployment of the XCharge C6.

Read the full article at CISA Advisories