Siemens Heliox EV chargers were disclosed to contain an improper access control weakness (CWE-923) that could allow an attacker with physical access to the charging interface to reach unauthorized services via the charging cable. CISA published an ICS advisory describing the issue and noting Siemens has released updated software versions; the advisory lists affected models including the Heliox Flex 180 kW EV Charging Station and Heliox Mobile DC 40 kW EV Charging Station, and scores the issue CVSS v3.1 2.6 (Low) with a vector indicating a physical attack requirement (e.g., AV:P). Siemens recommends updating to fixed versions and protecting device/network access per its industrial security operational guidelines.
Canada’s Centre for Cyber Security also highlighted Siemens’ March 2026 advisory set, including updates for Heliox Flex (prior to F4.11.1) and Heliox Mobile DC 40 (prior to L4.10.1), alongside unrelated Siemens product lines (e.g., Mendix, RUGGEDCOM, SIMATIC). A separate Canadian advisory covering Schneider Electric products (EcoStruxure and Modicon lines) is a different vendor’s disclosure and does not pertain to the Siemens Heliox EV charger vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-12, CISA republished Siemens ProductCERT advisory SSA-126399 describing an improper access control vulnerability in Siemens Heliox Flex 180 kW and Heliox Mobile DC 40 kW EV charging stations. The advisory said the flaw could allow access to unauthorized services via the charging cable and noted Siemens had released updated versions.
On 2026-03-10, Siemens published security advisories covering vulnerabilities in multiple products, including Heliox EV charging stations, Mendix Applications, RUGGEDCOM APE1808 deployments using Fortigate NGFW, SIDIS Prime, SICAM SIAPP SDK, and SIMATIC S7-1500. Siemens advised users to review the advisories, apply mitigations, and install necessary updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.