Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a critical security flaw in Autel Maxi Charger Single firmware that could allow an authenticated attacker to disrupt service or potentially execute their own code by providing overly large input. The main concern is confirming if this specific technology is in use within our organization and, if so, to what extent.
- Unauthorized input could disable chargers.
- Critical flaw found in a specific charger model.
- Confirm relevance and exposure of this technology.
Attack Path
How an attacker could exploit the issue
An attacker with low-level access to the Autel Maxi Charger can send specially crafted data to the local configuration endpoint. This data triggers a buffer overflow, which could lead to disruption of service or even allow the attacker to execute their own code on the device.
- Requires authenticated access.
- Triggered by oversized input to localcfg.
- Risk of code execution or denial of service.
Live Threat
Current exploitation, exposure, and threat context
An authenticated attacker with access to the `/localcfg` endpoint could exploit a heap-based buffer overflow in the `set_ap_param` command. This could disrupt the service's normal operation and potentially allow for arbitrary code execution when supported by the advisory.
- Service availability.
- Oversized input to specific command.
- Denial of service, code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Autel Maxi Charger Single firmware vulnerability requires a coordinated response. Application owners or the platform team responsible for managing the charger's firmware are likely to address this. The first practical step involves identifying all deployed Maxi Charger units, confirming their network reachability and business criticality, and then engaging the appropriate teams for remediation planning.
- Firmware owners should initiate discovery.
- Verify charger network exposure and criticality.
- Plan coordinated firmware updates.