Description
Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of card responses via the NFC interface. A crafted card response can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29044.
Published: 2026-07-29
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack‑based buffer overflow triggered by a crafted NFC card response. An attacker with physical proximity can insert a malicious card and cause the device to execute arbitrary code in its own context. The flaw resides in the NFC card response handling and does not require any prior authentication.

Affected Systems

The affected devices are Autel MaxiCharger AC Elite Home electric‑vehicle chargers. No specific firmware or hardware versions are listed, so all current installations should be considered vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity, and the EPSS score of less than 1% suggests exploitation is currently unlikely. Nevertheless, the vulnerability is listed as not in KEV and is exploitable without credentials, so a physically present attacker with NFC expertise could potentially gain full control of the charger. Because no public workaround is available, securing physical access and disabling NFC is an important mitigative step.

Generated by OpenCVE AI on August 3, 2026 at 12:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Autel’s official website or support channels for a firmware update that addresses the NFC stack‑overflow flaw and apply the patch as soon as it becomes available.
  • Disable the NFC reader on the charger or restrict its operation to authorized readers only, which removes the attack surface for crafted card responses.
  • Physically secure the charger by restricting access to authorized personnel and ensuring it is placed in a controlled environment to prevent tampering with the NFC interface.

Generated by OpenCVE AI on August 3, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Ac Elite Home
Vendors & Products Autel
Autel maxicharger Ac Elite Home

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of card responses via the NFC interface. A crafted card response can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29044.
Title Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability
Weaknesses CWE-121
References
Metrics cvssV3_0

{'score': 6.8, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Autel Maxicharger Ac Elite Home
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-30T15:18:49.098Z

Reserved: 2026-06-25T00:12:12.202Z

Link: CVE-2026-13309

cve-icon Vulnrichment

Updated: 2026-07-30T14:18:24.275Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T21:17:46.607

Modified: 2026-07-30T16:16:55.417

Link: CVE-2026-13309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:00:07Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow