Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability affects Autel Maxi Charger Single devices, allowing attackers to execute arbitrary commands on the charging station through a compromised or malicious server. The issue stems from how the device processes specific diagnostic requests, potentially leading to unauthorized control over charging infrastructure.
- Malicious servers can control charging stations.
- Critical vulnerability impacts charging station control.
- Confirm relevance and potential exposure of devices.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by controlling a charging station's backend server. This server, using the Open Charge Point Protocol, can send a specially crafted URL to the charging station. When the station processes this URL in a diagnostics request, it can be tricked into running arbitrary commands on its operating system.
- Network access required.
- Crafted diagnostics request triggers vulnerability.
- Leads to arbitrary command execution.
Live Threat
Current exploitation, exposure, and threat context
An attacker controlling an OCPP server could exploit this vulnerability by sending a specially crafted diagnostics URL to the charging station. This could lead to arbitrary command execution on the device, potentially impacting its operational integrity.
- Charging station operating system.
- Malicious URL via OCPP server.
- Arbitrary command execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Autel Maxi Charger firmware, allowing arbitrary command execution, likely requires coordination between the charging station's asset owner and the vendor to address. The first practical step is to identify all deployed charging stations, confirm their network exposure and business criticality, and then engage the vendor for a secure firmware update.
- Own by charging station asset owner.
- Verify network exposure and criticality.
- Coordinate vendor firmware update.