Input Misinterpretation Vulnerability in Autel MaxiCharger AC Wallbox Commercial
CVE-2025-5826
6.3MEDIUM
What is CVE-2025-5826?
The vulnerability in Autel MaxiCharger AC Wallbox Commercial arises from a flaw in the ble_process_esp32_msg function, where the device incorrectly interprets input data. This misinterpretation enables network-adjacent attackers to issue arbitrary AT commands without required authentication, potentially compromising the functionality and security of the charging stations. The implications of such unauthorized access could lead to a range of malicious actions executed within the device's operational context.
Affected Version(s)
Autel MaxiCharger AC Wallbox Commercial 1.36.00