ZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the device.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-13308.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-437
Event History
Frequently Asked Questions
What is the severity of ZDI-26-437?
The severity of ZDI-26-437 is considered high with a CVSS score of 8.1.
How do I fix ZDI-26-437?
To fix ZDI-26-437, update your Autel MaxiCharger AC Elite Home EV charger to the latest firmware version provided by the manufacturer.
What can attackers do with ZDI-26-437?
Attackers can execute arbitrary code remotely on affected installations of the Autel MaxiCharger AC Elite Home EV chargers.
Is authentication required to exploit ZDI-26-437?
No, authentication is not required to exploit the ZDI-26-437 vulnerability.
What type of flaw is ZDI-26-437?
ZDI-26-437 is classified as an integer underflow vulnerability related to WebSocket message handling.