CVE-2026-13305
Last modified
CVE-2026-13305 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of a user-supplied software update image. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29062.
Metrics
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Autel | MaxiCharger AC Elite Home | 1.39.51 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-13305?
How severe is CVE-2026-13305?
How do I fix CVE-2026-13305?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13281Integer overflow in Mojo in Google Chrome prior to 149.0.782…8.3
- CVE-2026-13282Use after free in Payments in Google Chrome on Android prior…6.8
- CVE-2026-13283Use after free in AdFilter in Google Chrome on Android prior…7.5
- CVE-2026-1329A flaw has been found in Tenda AX1803 1.0.0.1. The affected …8.8
- CVE-2026-13295The Page Builder by SiteOrigin plugin for WordPress is vulne…6.4
- CVE-2026-1330MeetingHub developed by HAMASTAR Technology has an Arbitrary…8.7
- CVE-2026-13306Autel MaxiCharger AC Elite Home USB Authentication Bypass Vu…4.3
- CVE-2026-13307Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overfl…6.8
- CVE-2026-13308Autel MaxiCharger AC Elite Home WebSockets Integer Underflow…8.1
- CVE-2026-13309Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overf…6.8
- CVE-2026-1331MeetingHub developed by HAMASTAR Technology has an Arbitrary…9.8
- CVE-2026-13311shell-quote prior to 1.8.5 finalizes parsed tokens in parse(…8.7
Are you affected by CVE-2026-13305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
