Information Disclosure Vulnerability in Autel MaxiCharger AC Wallbox by Autel
CVE-2025-5823

4.9MEDIUM

Key Information:

Vendor

Autel

Vendor
CVE Published:
25 June 2025

What is CVE-2025-5823?

The Autel MaxiCharger AC Wallbox exhibits a vulnerability within its Technician API that can be exploited by unauthorized remote attackers. This flaw arises from the presence of an exposed dangerous method, which permits the disclosure of sensitive installation information, including credentials. Consequently, such a breach can facilitate unauthorized access, potentially leading to further exploitation of the system. It is crucial for users and administrators of affected devices to take preventive measures to mitigate this risk and safeguard their electric vehicle charging operations.

Affected Version(s)

Autel MaxiCharger AC Wallbox Commercial 1.36.00

References

CVSS V3.0

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.