← Vulnerability feed

Vulnerability record · CVE-2024-7795 · published 21 August 2024

CVE-2024-7795: Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerability

Autel · Maxicharger Ac Elite Business C50 Firmware

Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the AppAuthenExchangeRandomNum BLE command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23384.

8.8 CVSS 3.1 High EPSS 0.53% · top 57.3% CWE-121 · Stack-based buffer overflowCWE-119 · Memory buffer overflow
8.8CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the AppAuthenExchangeRandomNum BLE command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23384.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.zerodayinitiative.com/advisories/ZDI-24-1154/ Third Party AdvisoryVDB Entry

Track CVE-2024-7795 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-5827Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all…EPSS 0.39%8.8CVE-2025-5830Autel maxicharger ac elite business c50 firmware heap-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows n…EPSS 0.39%8.8CVE-2025-5822Autel maxicharger ac elite business c50 firmware incorrect authorization vulnerabilityAutel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a…EPSS 0.41%8.8CVE-2024-23958Autel maxicharger ac elite business c50 firmware hard-coded credentials vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent att…EPSS 0.80%8.8CVE-2024-23957Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …EPSS 0.97%8.0CVE-2024-23959Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability al…EPSS 0.82%8.0CVE-2024-23967Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…EPSS 0.91%7.5CVE-2025-6678Autel maxicharger ac elite business c50 firmware missing authentication for critical function vulnerabilityAutel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2024-7795), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.