CVE-2025-6678: Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability
Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the Pile API. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose credentials, leading to further compromise. Was ZDI-CAN-26352.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Use network controls (e.g., firewall/ACL) to restrict access to Autel MaxiCharger AC Wallbox Commercial charging stations—especially the Pile API endpoints—to trusted management systems only, since authentication is not required to exploit the PIN-missing authentication information disclosure vulnerability (ZDI-CAN-26352).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6678?
CVE-2025-6678 is considered a medium-severity vulnerability due to its potential for sensitive information disclosure.
How do I fix CVE-2025-6678?
To fix CVE-2025-6678, ensure that authentication mechanisms are properly implemented on the Autel MaxiCharger AC Wallbox Commercial.
What types of information can be disclosed due to CVE-2025-6678?
CVE-2025-6678 allows remote attackers to access sensitive information from vulnerable Autel MaxiCharger AC Wallbox Commercial installations.
Are there any workarounds for CVE-2025-6678?
Currently, there are no documented workarounds for CVE-2025-6678 beyond applying the necessary authentication fixes.
What products are affected by CVE-2025-6678?
CVE-2025-6678 affects the Autel MaxiCharger AC Wallbox Commercial charging stations.