Autel vulnerabilities
5 CVEs tracked
Autel appears in our reporting within the context of electric vehicle charging stations. The reports detail a series of critical vulnerabilities discovered in Autel MaxiCharger AC Elite Home devices. This includes CVE-2026-13308 (unauthenticated WebSocket Remote Code Execution over the network), CVE-2026-13309 (proximity-based code execution via NFC), and CVE-2026-13305/13306/13307 (USB-based authentication bypass, buffer overflow, and improper software update signature verification). Defenders should focus on isolating these devices at the network level, restricting physical access, and immediately applying any available firmware updates from the vendor.
Azərbaycanca: Autel, elektrikli avtomobil doldurma stansiyaları kontekstində hesabatlarımızda görünür. Hesabatlar Autel MaxiCharger AC Elite Home cihazlarında aşkar edilmiş kritik zəifliklər seriyasını əhatə edir. Buraya CVE-2026-13308 (şəbəkə üzərindən autentifikasiyasız WebSocket Remote Code Execution), CVE-2026-13309 (NFC üzərindən fiziki yaxınlıqla kod icrası) və CVE-2026-13305/13306/13307 (USB interfeysi üzərindən autentifikasiyadan yan keçmə, bufer daşması və proqram yeniləmələrində imza yoxlaması səhvi) daxildir. Müdafiəçilər bu cihazları şəbəkə səviyyəsində təcrid etməyə, fiziki girişi məhdudlaşdırmağa və dərhal istehsalçı tərəfindən təqdim edilən proqram təminatı yeniləmələrini tətbiq etməyə diqqət yetirməlidir.
This vendor's CVEs5
This hub is built from skopnix's own reporting on Autel: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.