Authentication Bypass Vulnerability in Autel MaxiCharger AC Wallbox
CVE-2025-5824

5MEDIUM

Key Information:

Vendor

Autel

Vendor
CVE Published:
25 June 2025

What is CVE-2025-5824?

The Autel MaxiCharger AC Wallbox Commercial is susceptible to an authentication bypass vulnerability due to improper handling of Bluetooth pairing requests. Attackers, having gained the ability to pair a malicious Bluetooth device, can exploit this flaw to bypass authentication on the system. The vulnerability arises from inadequate validation of the origin of commands during Bluetooth pairing, potentially allowing unauthorized access to the device settings. It is crucial for users and organizations utilizing this product to implement security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Autel MaxiCharger AC Wallbox Commercial 1.36.00

References

CVSS V3.0

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5824 : Authentication Bypass Vulnerability in Autel MaxiCharger AC Wallbox