Impact
The flaw is a heap‑based buffer overflow in the set_ap_param command that the /localcfg endpoint processes. Because of the overflow, an attacker can supply an oversized payload, causing the device to crash or, if memory corruption is exploitable, arbitrary code may be executed. The primary impact is a denial of service with the possibility of arbitrary code execution.
Affected Systems
The vulnerability affects the Autel Maxi Charger Single firmware version V1.03.51. Only this specific device and firmware release are noted as susceptible.
Risk and Exploitability
The CVSS score of 9.4 marks it as a high‑severity issue, yet the EPSS score of less than 1% suggests that, as of now, exploitation attempts are rare. Based on the description, it is inferred that an authenticated attacker can potentially execute arbitrary code if the memory corruption can be exploited. The attacker must be authenticated to construct the overflow; this suggests the attack vector may involve authenticated access, which could be local or remote. While the risk is high, current likelihood is low and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment