CVE-2025-5826

MEDIUM
Published Jun 25, 2025 Modified Sep 10, 2025 CWE-115

Description

Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ble_process_esp32_msg function. The issue results from misinterpretation of input data. An attacker can leverage this vulnerability to execute AT commands in the context of the device. Was ZDI-CAN-26368.

CVSS v3.1 Score

6.3
MEDIUM
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weakness Type (CWE)

CWE-115 CWE-115

Affected Products

Vendor Product
autel maxicharger_ac_elite_business_c50_firmware
autel maxicharger_ac_elite_business_c50_firmware
autel maxicharger_ac_elite_business_c50
autel maxicharger_ac_pro_firmware
autel maxicharger_ac_pro_firmware
autel maxicharger_ac_pro
autel maxicharger_ac_ultra_firmware
autel maxicharger_ac_ultra_firmware
autel maxicharger_ac_ultra
autel maxicharger_dc_compact_mobile_firmware
autel maxicharger_dc_compact_mobile_firmware
autel maxicharger_dc_compact_mobile
autel maxicharger_dc_compact_pedestal_firmware
autel maxicharger_dc_compact_pedestal_firmware
autel maxicharger_dc_compact_pedestal
autel maxicharger_dc_fast_firmware
autel maxicharger_dc_fast_firmware
autel maxicharger_dc_fast
autel maxicharger_dc_hipower_firmware
autel maxicharger_dc_hipower_firmware
autel maxicharger_dc_hipower
autel maxicharger_dh480_firmware
autel maxicharger_dh480_firmware
autel maxicharger_dh480
autel maxicharger_single_charger_firmware
autel maxicharger_single_charger_firmware
autel maxicharger_single_charger

References

Frequently Asked Questions

What is CVE-2025-5826? +
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ble_process_esp32_msg function. The issue results from misinterpretation of input data. An attacker can leverage this vulnerability to execute AT commands in the context of the device. Was ZDI-CAN-26368. It has a CVSS v3.1 base score of 6.3 (MEDIUM).
How severe is CVE-2025-5826? +
CVE-2025-5826 has a CVSS v3.1 score of 6.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-5826? +
CVE-2025-5826 affects products from autel, specifically: maxicharger_ac_elite_business_c50, maxicharger_ac_elite_business_c50_firmware, maxicharger_ac_pro, maxicharger_ac_pro_firmware, maxicharger_ac_ultra, maxicharger_ac_ultra_firmware, maxicharger_dc_compact_mobile, maxicharger_dc_compact_mobile_firmware, maxicharger_dc_compact_pedestal, maxicharger_dc_compact_pedestal_firmware, maxicharger_dc_fast, maxicharger_dc_fast_firmware, maxicharger_dc_hipower, maxicharger_dc_hipower_firmware, maxicharger_dh480, maxicharger_dh480_firmware, maxicharger_single_charger, maxicharger_single_charger_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-5826? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-5826 — free, no signup required.

Start Free Scan