Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability involves a hard-coded authentication token in Autel Maxi Charger devices, allowing unauthenticated access to sensitive management functions. The issue impacts technology used for electric vehicle charging infrastructure. The primary concern is to confirm if these devices are in use and if they are exposed to potential unauthorized access.
- Hard-coded token bypasses authentication for chargers.
- Critical to confirm if charging devices are exposed.
- Understand risk; confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can reach and trigger this vulnerability by interacting with the device over the network. No authentication is needed to access specific management functions because a hard-coded token bypasses authorization checks. This allows an attacker to invoke privileged operations, potentially leading to unauthorized control or data access.
- Network access required.
- Special token bypasses authorization.
- Unauthenticated privileged function access.
Live Threat
Current exploitation, exposure, and threat context
The Autel Maxi Charger Single's hard-coded authentication token could allow an unauthorized attacker to access and control management functions. This could occur when the device is accessible over a network, potentially enabling unauthorized operations or configuration changes. No specific PII or sensitive data types are mentioned as being at risk.
- Management endpoints and functions.
- Via network access by supplying a special token.
- Unauthorized control of charging functions.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Autel Maxi Charger Single firmware's hard-coded authentication token presents a critical risk, allowing unauthenticated access to privileged functions. Ownership likely falls to teams managing operational technology (OT) or industrial control systems (ICS), potentially collaborating with network and security teams. The first practical step is to identify all deployed Maxi Charger units, determine their network exposure, and confirm which are actively managed or remotely accessible.
- Identify affected devices and their exposure.
- Confirm device ownership and criticality.
- Plan vendor engagement for firmware updates.