Junglewise Threat Intelligence

CVE-2026-13306: Autel MaxiCharger AC Elite Home authentication bypass in USB interface

CVE-2026-13306 · Severity: medium · CVSS 4.3 · Published 2026-07-29

Technologies: Autel MaxiCharger AC Elite Home. Vendors: Autel.

Executive brief

A security vulnerability in Autel MaxiCharger AC Elite Home electric vehicle chargers allows an individual with physical access to the device to bypass security controls. By connecting to the charger's exposed USB port, an unauthorized person can access internal system functions without providing a password or credentials. This could lead to unauthorized configuration changes or disruption of the charging service.

Technical details

A missing authentication vulnerability (CWE-306) exists in the USB interface of the Autel MaxiCharger AC Elite Home EV charger. The flaw is located within the exposed USB port, which fails to require authentication before granting access to system functionality. An attacker with physical access can exploit this lack of access control to bypass authentication mechanisms entirely. The vulnerability was identified in firmware version 1.39.51 and has been addressed in firmware version V1.40.81. Exploitation requires physical proximity to the device but no prior administrative privileges.

Affected products

  • Autel MaxiCharger AC Elite Home 1.39.51

Timeline

  • 2026-03-19: disclosed: Vulnerability reported to vendor
  • 2026-07-15: patched: Fixed in firmware version V1.40.81
  • 2026-07-15: advisory: Coordinated public release of advisory by ZDI

References

Related threats