ClosedLow impactAI Generated

CISA Advisory: XCharge C6 EV Charger Critical Vulnerabilities

Occurred 28 May 2026·Detected 28 May 2026·
🇺🇸 Worldwide deployment; XCharge headquartered in United States1 reportEnded 29 May 2026
CyberPropertyCyberCasualty & Liability

CISA has published an ICS advisory disclosing three critical/high-severity vulnerabilities in the XCharge C6 EV charging controller, including a firmware integrity bypass (CVSS 9.8), stack-based buffer overflow, and insecure default credential flaw. The vulnerabilities affect chargers deployed worldwide and could allow remote or physical attackers to gain administrator rights or execute arbitrary code. XCharge has confirmed patches have been deployed, and no known public exploitation has been reported at this time.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. No concrete London Market loss pathway is evidenced: no named insured asset damage, no confirmed exploitation, no business interruption, no claims or reserving activity indicated. Patches have already been deployed by the vendor. The advisory is a routine ICS vulnerability disclosure with theoretical relevance to cyber underwriters monitoring EV/transportation infrastructure exposure, but falls below the threshold for MEDIUM without evidence of active exploitation, insured loss, or named commercial asset impact.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

3 active matches

  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • Pacific Ring of Fire
    Rule-basedConfidence 100%
  • Caribbean Hurricane Zone
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts