Impact
The vulnerability allows a physically present attacker to bypass the authentication mechanism on Autel MaxiCharger AC Elite Home EV chargers through the exposed USB interface. Because the system does not require authentication before granting access to its functionalities, an attacker can potentially trigger any USB‑handled operation without permission. The impact is an unauthorized use of charger functions, which could lead to improper charging, data leakage, or other operational disruptions.
Affected Systems
Autel MaxiCharger AC Elite Home electric vehicle chargers accessed via the USB port. No specific version information has been disclosed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is physical; the attacker must have direct access to the USB interface to inject commands and override authentication checks.
OpenCVE Enrichment