Security Advisory

CVE-2026-9039

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-05-28 19:07:09
Last updated 2026-05-28 19:07:09
Assigner icscert
State PUBLISHED

Description

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.