Impact
Autel MaxiCharger AC Elite Home EV chargers suffer from a failure to properly validate the cryptographic signature of software update images. Because the device accepts an unsigned or tampered update, an attacker can install malicious code that runs with the full privileges of the charger, potentially allowing the attacker to take control of the device or alter its behavior. No authentication is required to deliver the update, so the vulnerability permits arbitrary code execution without remote logon or network authentication.
Affected Systems
The flaw targets all installations of the Autel MaxiCharger AC Elite Home product line. No specific firmware versions are listed in the advisory, so any unit that accepts unsigned update files is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the wild at this time. The attacker must be physically present to provide the malicious update, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, because the flaw enables arbitrary code execution, it poses a serious risk if an attacker can access the charger.
OpenCVE Enrichment