CVE-2025-5826
MEDIUMDescription
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ble_process_esp32_msg function. The issue results from misinterpretation of input data. An attacker can leverage this vulnerability to execute AT commands in the context of the device. Was ZDI-CAN-26368.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| autel | maxicharger_ac_elite_business_c50_firmware |
| autel | maxicharger_ac_elite_business_c50_firmware |
| autel | maxicharger_ac_elite_business_c50 |
| autel | maxicharger_ac_pro_firmware |
| autel | maxicharger_ac_pro_firmware |
| autel | maxicharger_ac_pro |
| autel | maxicharger_ac_ultra_firmware |
| autel | maxicharger_ac_ultra_firmware |
| autel | maxicharger_ac_ultra |
| autel | maxicharger_dc_compact_mobile_firmware |
| autel | maxicharger_dc_compact_mobile_firmware |
| autel | maxicharger_dc_compact_mobile |
| autel | maxicharger_dc_compact_pedestal_firmware |
| autel | maxicharger_dc_compact_pedestal_firmware |
| autel | maxicharger_dc_compact_pedestal |
| autel | maxicharger_dc_fast_firmware |
| autel | maxicharger_dc_fast_firmware |
| autel | maxicharger_dc_fast |
| autel | maxicharger_dc_hipower_firmware |
| autel | maxicharger_dc_hipower_firmware |
| autel | maxicharger_dc_hipower |
| autel | maxicharger_dh480_firmware |
| autel | maxicharger_dh480_firmware |
| autel | maxicharger_dh480 |
| autel | maxicharger_single_charger_firmware |
| autel | maxicharger_single_charger_firmware |
| autel | maxicharger_single_charger |
References
Other References
Frequently Asked Questions
What is CVE-2025-5826? +
How severe is CVE-2025-5826? +
What products are affected by CVE-2025-5826? +
How do I check if I'm vulnerable to CVE-2025-5826? +
Related Vulnerabilities
WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …
An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module …
A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, …
Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud …
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload …
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP …