PT-2026-60344 · Autel · Maxicharger Ac Elite Home

CVE-2026-13308

·

Published

2026-07-15

·

Updated

2026-07-29

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autel MaxiCharger AC Elite Home (affected versions not specified)
Description Remote attackers can execute arbitrary code on affected EV chargers without authentication. The issue occurs during the handling of WebSocket messages related to the OCPP (Open Charge Point Protocol) service, where a lack of proper validation of user-supplied data leads to an integer underflow before buffer allocation. This allows the attacker to execute code within the device context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13308
ZDI-26-437

Affected Products

Maxicharger Ac Elite Home