Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability. The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.
History

Wed, 10 Sep 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Ac Elite Business C50
Autel maxicharger Ac Elite Business C50 Firmware
Autel maxicharger Ac Pro
Autel maxicharger Ac Pro Firmware
Autel maxicharger Ac Ultra
Autel maxicharger Ac Ultra Firmware
Autel maxicharger Dc Compact Mobile
Autel maxicharger Dc Compact Mobile Firmware
Autel maxicharger Dc Compact Pedestal
Autel maxicharger Dc Compact Pedestal Firmware
Autel maxicharger Dc Fast
Autel maxicharger Dc Fast Firmware
Autel maxicharger Dc Hipower
Autel maxicharger Dc Hipower Firmware
Autel maxicharger Dh480
Autel maxicharger Dh480 Firmware
Autel maxicharger Single Charger
Autel maxicharger Single Charger Firmware
CPEs cpe:2.3:h:autel:maxicharger_ac_elite_business_c50:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_ac_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_ac_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_dc_compact_mobile:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_dc_compact_pedestal:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_dc_fast:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_dc_hipower:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_dh480:-:*:*:*:*:*:*:*
cpe:2.3:h:autel:maxicharger_single_charger:-:*:*:*:*:*:*:*
cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_ac_pro_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_ac_pro_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_ac_ultra_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_ac_ultra_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_dc_compact_mobile_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_dc_compact_mobile_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_dc_compact_pedestal_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_dc_compact_pedestal_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_dc_fast_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_dc_fast_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_dc_hipower_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_dc_hipower_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_dh480_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_dh480_firmware:*:*:*:*:*:*:*:european_standard
cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:american_standard
cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:european_standard
Vendors & Products Autel
Autel maxicharger Ac Elite Business C50
Autel maxicharger Ac Elite Business C50 Firmware
Autel maxicharger Ac Pro
Autel maxicharger Ac Pro Firmware
Autel maxicharger Ac Ultra
Autel maxicharger Ac Ultra Firmware
Autel maxicharger Dc Compact Mobile
Autel maxicharger Dc Compact Mobile Firmware
Autel maxicharger Dc Compact Pedestal
Autel maxicharger Dc Compact Pedestal Firmware
Autel maxicharger Dc Fast
Autel maxicharger Dc Fast Firmware
Autel maxicharger Dc Hipower
Autel maxicharger Dc Hipower Firmware
Autel maxicharger Dh480
Autel maxicharger Dh480 Firmware
Autel maxicharger Single Charger
Autel maxicharger Single Charger Firmware
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 26 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Description Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability. The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.
Title Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability
Weaknesses CWE-863
References
Metrics cvssV3_0

{'score': 7.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2025-06-25T18:00:49.179Z

Updated: 2025-06-26T13:18:05.218Z

Reserved: 2025-06-06T19:16:34.664Z

Link: CVE-2025-5822

cve-icon Vulnrichment

Updated: 2025-06-26T13:18:01.808Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-25T18:15:22.900

Modified: 2025-09-10T14:46:51.023

Link: CVE-2025-5822

cve-icon Redhat

No data.