PT-2025-25249 · Autel · Autel Maxicharger Ac Wallbox Commercial

Felix Buchmann

+2

·

Published

2025-06-11

·

Updated

2025-06-25

·

CVE-2025-5829

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autel MaxiCharger AC Wallbox Commercial autocharge (affected versions not specified)
Description The issue is a stack-based buffer overflow that allows for remote code execution. It was discovered by Tobias Scharnowski, Felix Buchmann, and Kristian Covic. The vulnerability was demonstrated at Pwn2Own.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-5829
ZDI-25-348

Affected Products

Autel Maxicharger Ac Wallbox Commercial