CVE-2026-22540: Efacec QC60/90/120

Critical severity, CVSS 9.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

Affected products

  • Efacec QC60/90/120: version 8 only

Published 2026-01-07. Last modified 2026-06-17.