CVE-2026-13308

Autel · MaxiCharger AC Elite Home

A remote code execution vulnerability exists in the Autel MaxiCharger AC Elite Home due to an integer underflow in the WebSockets implementation.

Executive summary

An integer underflow vulnerability in the Autel MaxiCharger AC Elite Home can lead to remote code execution by unauthenticated attackers.

Vulnerability

The device is susceptible to an integer underflow (CWE-191) within its WebSockets handling process. This allows a remote, unauthenticated attacker to trigger a memory corruption condition, potentially resulting in arbitrary code execution.

Business impact

With a CVSS score of 8.1, this vulnerability presents a critical threat to the operational security of the charging infrastructure. Successful exploitation allows for full system compromise, which could be leveraged to disrupt charging services or gain persistence within the local network environment.

Remediation

Immediate Action: Contact the vendor for specific firmware update instructions, as a patch version is not currently identified in public records.

Proactive Monitoring: Monitor for unusual network traffic patterns or repeated crashes of the charger management interface, which may indicate exploitation attempts.

Compensating Controls: Restrict access to the charger management interface via a firewall, ensuring it is not directly reachable from the public internet.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a severe risk of unauthorized remote control over physical infrastructure. Organizations should immediately restrict network access to the affected devices and coordinate with Autel support to determine the availability and installation procedure for the necessary security firmware.