Autel manufactures electric vehicle charging stations, primarily its MaxiCharger product line, which includes both AC and DC variants deployed across commercial and mobile charging infrastructure. The vendor's vulnerability exposure centers on memory-safety issues endemic to embedded device firmware, with recurring stack-based and heap-based buffer overflows, out-of-bounds writes, and exposed dangerous functions reflecting the low-level control-systems nature of charging-station software. Defenders managing Autel charging infrastructure should prioritize firmware updates and network segmentation for these devices; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autel over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23958HIGH Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication | Sep 28, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-23957HIGH Autel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to e | Sep 28, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-5830HIGH Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to ex | Jun 25, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-5827HIGH Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers | Jun 25, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-7795HIGH Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attac | Aug 21, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-5822HIGH Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges | Jun 25, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-23967HIGH Autel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack | Sep 28, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-23959HIGH Autel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers | Sep 28, 2024 | 8.0 | 23 | NO | NO |
CVE-2025-6678HIGH Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio | Jun 25, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-5825HIGH Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on af | Jun 25, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autel.
Media articles that mention a CVE ID that affects a product developed by Autel — matched by CVE ID, not by vendor name.