CVE-2025-5825: (Pwn2Own) Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability
Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.
The specific flaw exists within the firmware update process. The issue results from the lack of proper validation of a firmware image before using it to perform an upgrade. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-26354.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5825?
The severity of CVE-2025-5825 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2025-5825?
To fix CVE-2025-5825, update the Autel MaxiCharger AC Wallbox Commercial firmware to the latest version as provided by the vendor.
Who is affected by CVE-2025-5825?
Organizations using Autel MaxiCharger AC Wallbox Commercial charging stations are affected by CVE-2025-5825.
Can CVE-2025-5825 be exploited remotely?
Yes, CVE-2025-5825 can be exploited remotely by network-adjacent attackers to execute arbitrary code.
What is the potential impact of CVE-2025-5825?
The potential impact of CVE-2025-5825 includes unauthorized access to the charging station and execution of malicious commands.