CVE-2025-5822: (Pwn2Own) Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability.
The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5822?
CVE-2025-5822 is classified as a critical vulnerability due to its potential for remote privilege escalation.
How do I fix CVE-2025-5822?
To fix CVE-2025-5822, ensure that your Autel MaxiCharger AC Wallbox Commercial devices are updated with the latest security patches provided by Autel.
Who is affected by CVE-2025-5822?
CVE-2025-5822 affects installations of Autel MaxiCharger AC Wallbox Commercial charging stations.
What type of attacks can exploit CVE-2025-5822?
CVE-2025-5822 can be exploited by remote attackers to escalate privileges on affected systems.
Is authentication required to exploit CVE-2025-5822?
No, CVE-2025-5822 allows exploitation without proper authentication, increasing the risk of unauthorized access.