A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.
History

Thu, 28 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic signatures are not verified, an attacker with the ability to interfere with or impersonate the management channel could cause the device to install an unauthorized firmware package. This condition could allow execution of unauthorized code with high privileges on the device.
Title Download of code without integrity check in XCharge C6
Weaknesses CWE-494
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-05-28T19:04:14.794Z

Reserved: 2026-05-19T16:54:38.351Z

Link: CVE-2026-9037

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T20:16:27.093

Modified: 2026-05-28T20:16:27.093

Link: CVE-2026-9037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.