What is CVE-2026-13307?
CVE-2026-13307 is a heap-based buffer overflow vulnerability in the USB functionality of Autel MaxiCharger AC Elite Home EV chargers. It allows physically present attackers to execute arbitrary code without authentication. Users should apply firmware updates provided by the vendor.
Azərbaycanca: CVE-2026-13307, Autel MaxiCharger AC Elite Home EV yükləmə cihazlarında USB portu üzərindən heap-based buffer overflow zəifliyidir. Bu qüsur fiziki çıxışı olan şəxslərə autentifikasiya olmadan ixtiyari kod icrasına imkan verir. İstehsalçı tərəfindən buraxılmış proqram təminatı yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Autel
FAQ2
What physical access is required to exploit CVE-2026-13307?
The attacker must have physical access to the Autel MaxiCharger AC Elite Home EV charger, as the vulnerability is exploited via the device's USB port.
What is the primary mitigation recommended by the vendor for CVE-2026-13307?
Users should apply the firmware updates provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.