Executive brief
Autel MaxiCharger electric vehicle charging stations contain a hard-coded security token that allows anyone to bypass normal login requirements. By using this secret token, an unauthorized person can access management interfaces to change device configurations or access sensitive charging data. This could lead to a complete loss of control over the charging infrastructure and potential service disruptions.
Technical details
The Autel MaxiCharger Single firmware (up to V1.03.51) contains a hard-coded authentication bypass vulnerability (CWE-798). The device's management endpoints, such as '/localcfg', fail to properly validate session tokens if a specific hard-coded string ('Nut666') is provided in the 'token' field of a JSON POST request. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to the device's management interface. Successful exploitation allows the attacker to bypass authorization checks, modify system configurations, and access privileged commands (e.g., 'get_pm_data') without possessing valid user credentials.
Affected products
- Autel MaxiCharger Single through V1.03.51
Timeline
- 2026-07-21: advisory: NVD publication date
- 2026-09-06: disclosed: CyberDanube research publication date