Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
Summary
| CVE | CVE-2026-13306 |
|---|---|
| State | PUBLISHED |
| Assigner | zdi |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-29 21:17:46 UTC |
| Updated | 2026-07-30 16:16:55 UTC |
| Description | Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the exposed USB interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29046. |
Risk And Classification
Primary CVSS: v3.0 4.3 MEDIUM from [email protected]
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS: 0.001830000 probability, percentile 0.081050000 (date 2026-08-01)
Problem Types: CWE-306 | CWE-306 CWE-306: Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Secondary | 4.3 | MEDIUM | CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| 3.0 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
CVSS v3.0 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Autel | MaxiCharger AC Elite Home | affected 1.39.51 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.zerodayinitiative.com/advisories/ZDI-26-434 | [email protected] | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.