OCTOBER 3, 2026
Live Feed
Back to database
Case File

CVE-2026-9039

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-28 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It may be remotely exploitable.

CVE
CVE-2026-9039
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%

Original NVD Description

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and it accepts a default administrative credential. A malicious device physically connected to the charging interface could leverage this misconfiguration to obtain full administrative access.