RCE by Design: When Firmware Updates Become the Attack
SaiFlow's research uncovered an undocumented firmware update mechanism in XCharge C6 chargers that relies solely on attacker-controlled MD5 validation and executes embedded scripts as root, effectively enabling remote code execution through malicious firmware delivered via compromised servers, man-in-the-middle attacks, or CSMS compromise.