CISA Advisory: XCharge C6 EV Charger Critical Vulnerabilities
CISA has published an ICS advisory disclosing three critical/high-severity vulnerabilities in the XCharge C6 EV charging controller, including a firmware integrity bypass (CVSS 9.8), stack-based buffer overflow, and insecure default credential flaw. The vulnerabilities affect chargers deployed worldwide and could allow remote or physical attackers to gain administrator rights or execute arbitrary code. XCharge has confirmed patches have been deployed, and no known public exploitation has been reported at this time.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. No concrete London Market loss pathway is evidenced: no named insured asset damage, no confirmed exploitation, no business interruption, no claims or reserving activity indicated. Patches have already been deployed by the vendor. The advisory is a routine ICS vulnerability disclosure with theoretical relevance to cyber underwriters monitoring EV/transportation infrastructure exposure, but falls below the threshold for MEDIUM without evidence of active exploitation, insured loss, or named commercial asset impact.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts