Executive brief
A security vulnerability has been identified in Autel MaxiCharger AC Elite Home electric vehicle chargers. An attacker with physical access to the device's USB port could potentially take control of the charger and execute unauthorized commands. This could lead to a complete compromise of the device's operations or unauthorized access to its internal systems.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Autel MaxiCharger AC Elite Home EV charger firmware version 1.39.51. The flaw is located in the handling of custom USB packets, where the device fails to properly validate the length of user-supplied data before copying it into a fixed-length heap buffer. A physically present attacker can exploit this by sending specially crafted USB packets to the device. Successful exploitation allows for arbitrary code execution in the context of the device without requiring prior authentication. The issue is resolved in firmware version V1.40.81.
Affected products
- Autel MaxiCharger AC Elite Home 1.39.51
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-15: patched: Fixed in firmware version V1.40.81
- 2026-07-15: advisory: Coordinated public release of advisory by ZDI
- 2026-07-29: other: NVD publication date