Horizon Alert
Summary of the vulnerability and why it matters
An undocumented vulnerability exists in Autel Maxi Charger Single firmware, allowing unauthenticated attackers to gain administrative control. This occurs due to two hidden administrative accounts that use a predictable password generation method.
- Hidden accounts allow unauthorized admin access.
- Critical for securing EV charging infrastructure.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker could gain administrative access to the Autel Maxi Charger's web management interface by exploiting two undocumented privileged accounts. This is possible if the attacker knows the specific algorithm and device-dependent inputs used to derive the passwords for these accounts. Successful authentication would grant them full control over the charging station.
- No specific access required.
- Authenticate to web management interface.
- Full administrative control.
Live Threat
Current exploitation, exposure, and threat context
An attacker could gain administrative access to the web management interface by leveraging undocumented privileged accounts in the Autel Maxi Charger Single firmware. This is possible when the attacker possesses knowledge of the proprietary password derivation algorithm and the necessary device-specific inputs, allowing them to bypass standard authentication.
- Administrative access to the web interface.
- Authentication bypass using proprietary algorithms.
- Unauthorized control of charging station functions.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Autel Maxi Charger Single firmware contains undocumented privileged accounts that could allow unauthorized administrative access. Ownership likely falls to the device owner or the team managing the charging infrastructure, possibly with vendor support. The first practical step is to identify all deployed charging stations, assess their network exposure and business criticality, and then engage the accountable owner for a coordinated remediation plan.
- Device owners or infrastructure teams should own the issue.
- Verify network exposure and business criticality first.
- Plan vendor-coordinated firmware updates or mitigation.