← Vulnerability feed

Vulnerability record · CVE-2024-23958 · published 28 September 2024

CVE-2024-23958: Autel maxicharger ac elite business c50 firmware hard-coded credentials vulnerability

Autel · Maxicharger Ac Elite Business C50 Firmware

Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BLE AppAuthenRequest command handler. The handler uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23196

8.8 CVSS 3.1 High EPSS 0.80% · top 45.3% CWE-798 · Hard-coded credentials
8.8CVSS 3.1 base score
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the BLE AppAuthenRequest command handler. The handler uses hardcoded credentials as a fallback in case of an authentication request failure. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23196

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.zerodayinitiative.com/advisories/ZDI-24-852/ Third Party AdvisoryVDB Entry

Track CVE-2024-23958 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-5827Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all…EPSS 0.39%8.8CVE-2025-5830Autel maxicharger ac elite business c50 firmware heap-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows n…EPSS 0.39%8.8CVE-2025-5822Autel maxicharger ac elite business c50 firmware incorrect authorization vulnerabilityAutel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a…EPSS 0.41%8.8CVE-2024-23957Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …EPSS 0.97%8.8CVE-2024-7795Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit…EPSS 0.53%8.0CVE-2024-23959Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability al…EPSS 0.82%8.0CVE-2024-23967Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…EPSS 0.91%7.5CVE-2025-6678Autel maxicharger ac elite business c50 firmware missing authentication for critical function vulnerabilityAutel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2024-23958), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.