Executive brief
A vulnerability has been identified in Autel MaxiCharger AC Elite Home electric vehicle chargers that could allow an unauthorized person to take control of the device over a network. By sending specially crafted messages, an attacker could execute their own code on the charger without needing any login credentials. This could lead to a complete compromise of the device, potentially impacting charging operations and local network security.
Technical details
An integer underflow vulnerability exists in the Autel MaxiCharger AC Elite Home EV charger within the handling of WebSocket messages for the Open Charge Point Protocol (OCPP) service. The flaw is caused by a lack of proper validation of user-supplied data, which leads to an integer underflow during buffer allocation. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution in the context of the device. The vulnerability is addressed in firmware version V1.40.81.
Affected products
- Autel MaxiCharger AC Elite Home 1.39.51
Timeline
- 2026-03-19: disclosed: Vulnerability reported to vendor
- 2026-07-15: patched: Fixed in firmware version V1.40.81
- 2026-07-15: advisory: Coordinated public release of advisory