What is CVE-2026-13308?
This is a critical remote code execution vulnerability in Autel MaxiCharger AC Elite Home EV chargers, exploitable via the WebSocket protocol without authentication. It allows attackers to fully compromise the device, making immediate firmware updates from the vendor essential to mitigate the risk.
Azərbaycanca: Bu boşluq, Autel MaxiCharger AC Elite Home elektrikli avtomobil enerji doldurucularında mövcud olan WebSocket protokolu üzərindən uzaqdan kod icrasına imkan verən təhlükəli bir zəiflikdir. Təsdiqləmə tələb etmədən sui-istifadə edilə biləcəyi üçün cihazın tam ələ keçirilməsinə səbəb ola bilər, buna görə istehsalçıdan gələn təhlükəsizlik yeniləməsi dərhal tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ1
How can CVE-2026-13308 affect the Autel MaxiCharger AC Elite Home device?
This vulnerability allows attackers to fully compromise the device by performing remote code execution (RCE) over the WebSocket protocol without authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.