Junglewise Threat Intelligence

CVE-2026-13309: Autel MaxiCharger AC Elite Home stack overflow in NFC stack

CVE-2026-13309 · Severity: medium · CVSS 6.8 · Published 2026-07-29

Technologies: Autel MaxiCharger AC Elite Home. Vendors: Autel.

Executive brief

The Autel MaxiCharger AC Elite Home is an electric vehicle (EV) charging station. A security flaw in its NFC card reader allows a person physically present at the charger to take control of the device by using a specially crafted NFC card. This could lead to unauthorized access to the charger's functions, potential service disruption, or the compromise of the device's internal software.

Technical details

A stack-based buffer overflow vulnerability exists in the NFC stack of the Autel MaxiCharger AC Elite Home EV charger. The flaw is located in the handling of card responses via the NFC interface, where the system fails to properly validate the length of data before copying it into a fixed-length stack buffer. A physically present attacker can exploit this by presenting a malicious NFC card that provides a crafted response, leading to arbitrary code execution in the context of the device. No authentication or user interaction is required beyond the physical proximity needed to interact with the NFC reader. The vulnerability is addressed in firmware version V1.40.81.

Affected products

  • Autel MaxiCharger AC Elite Home 1.39.51

Timeline

  • 2026-03-19: disclosed: Vulnerability reported to vendor
  • 2026-07-15: patched: Fixed in firmware version V1.40.81
  • 2026-07-15: advisory: Coordinated public release of advisory by ZDI
  • 2026-07-29: other: NVD publication date

References

Related threats