Description
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of a user-supplied software update image. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29062.
Published: 2026-07-29
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Autel MaxiCharger AC Elite Home EV chargers suffer from a failure to properly validate the cryptographic signature of software update images. Because the device accepts an unsigned or tampered update, an attacker can install malicious code that runs with the full privileges of the charger, potentially allowing the attacker to take control of the device or alter its behavior. No authentication is required to deliver the update, so the vulnerability permits arbitrary code execution without remote logon or network authentication.

Affected Systems

The flaw targets all installations of the Autel MaxiCharger AC Elite Home product line. No specific firmware versions are listed in the advisory, so any unit that accepts unsigned update files is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the wild at this time. The attacker must be physically present to provide the malicious update, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, because the flaw enables arbitrary code execution, it poses a serious risk if an attacker can access the charger.

Generated by OpenCVE AI on August 3, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Autel firmware update that addresses the signature verification flaw.
  • Configure the charger to reject or block unsigned or unauthorized update files if the firmware allows such a setting.
  • Restrict physical access to the charger so that only authorized personnel can attempt to apply software updates.

Generated by OpenCVE AI on August 3, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Ac Elite Home
Vendors & Products Autel
Autel maxicharger Ac Elite Home

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of a user-supplied software update image. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29062.
Title Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability
Weaknesses CWE-347
References
Metrics cvssV3_0

{'score': 6.4, 'vector': 'CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Autel Maxicharger Ac Elite Home
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-30T17:39:10.526Z

Reserved: 2026-06-25T00:12:00.171Z

Link: CVE-2026-13305

cve-icon Vulnrichment

Updated: 2026-07-30T16:12:26.781Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T21:17:46.093

Modified: 2026-07-30T19:17:06.113

Link: CVE-2026-13305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:00:07Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature