August 3, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-9039NVD

Vulnerability Summary

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.
Severity Level
UNKNOWN
Published Date
May 28, 2026
Last Modified
May 29, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.19%Probability
Root Weakness (CWE)
N/A