Executive brief
Autel MaxiCharger Single electric vehicle charging stations are vulnerable to a critical security flaw that allows unauthorized individuals to take complete control of the device over a network. By sending a specially crafted request to a specific service on the charger, an attacker can force the device to download and run malicious software. This could lead to a total service outage, theft of data, or the use of the charging infrastructure for further attacks on the corporate network.
Technical details
A remote code execution vulnerability exists in the Autel MaxiCharger Single firmware (up to V1.03.51) due to improper handling of requests in a service listening on TCP port 9002. An unauthenticated attacker can send a HTTP POST request to the '/test' endpoint containing JSON data with a URL pointing to a malicious archive. The device's service will download the archive, extract its contents, and execute a script named 'install.sh' with root privileges. This allows for full system compromise without requiring valid credentials or user interaction. The vulnerability is tracked as CWE-94 (Improper Control of Generation of Code).
Affected products
- Autel MaxiCharger Single through V1.03.51
Timeline
- 2026-07-21: advisory: NVD publication date
- 2026-09-06: disclosed: CyberDanube research publication date