Junglewise Threat Intelligence

CVE-2026-13305: Autel MaxiCharger AC Elite Home signature bypass in software update

CVE-2026-13305 · Severity: medium · CVSS 6.4 · Published 2026-07-29

Technologies: Autel MaxiCharger AC Elite Home. Vendors: Autel.

Executive brief

The Autel MaxiCharger AC Elite Home, an electric vehicle charging station, is vulnerable to a security flaw in its software update process. A person with physical access to the charger can install a malicious software update, allowing them to take full control of the device. This could lead to unauthorized use of the charger, service disruption, or the theft of data stored on the device.

Technical details

A vulnerability exists in the software update mechanism of the Autel MaxiCharger AC Elite Home EV charger (specifically version 1.39.51). The device fails to properly validate the cryptographic signature of user-supplied software update images (CWE-347). A physically present attacker can provide a modified firmware image that the device will accept and execute. Successful exploitation allows for arbitrary code execution in the context of the device's operating system. The vulnerability was addressed in firmware version V1.40.81.

Affected products

  • Autel MaxiCharger AC Elite Home 1.39.51

Timeline

  • 2026-03-19: disclosed: Vulnerability reported to vendor
  • 2026-07-15: patched: Fixed in firmware version V1.40.81
  • 2026-07-15: advisory: Coordinated public release of advisory by ZDI

References

Related threats