ZDI-CAN-29046: ZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the exposed USB interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13306.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict physical access to affected Autel MaxiCharger AC Elite Home EV chargers (USB interface) to prevent physically present attackers from exploiting the authentication bypass.
- Operational
Check for exposure to the affected charger models and apply the vendor’s remediation for CVE-2026-13306 (ZDI-26-434), since authentication is not required to exploit the USB interface flaw.
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29046?
The severity of ZDI-CAN-29046 is classified as medium with a score of 4.3.
How do I fix ZDI-CAN-29046?
To fix ZDI-CAN-29046, users should apply the latest firmware updates provided by Autel for the MaxiCharger AC Elite Home EV chargers.
What systems are affected by ZDI-CAN-29046?
ZDI-CAN-29046 affects the Autel MaxiCharger AC Elite Home EV chargers.
What type of vulnerability is ZDI-CAN-29046?
ZDI-CAN-29046 is an authentication bypass vulnerability that can be exploited via the exposed USB interface.
Who can exploit ZDI-CAN-29046?
ZDI-CAN-29046 can be exploited by physically present attackers without the need for authentication.