← Vulnerability feed

Vulnerability record · CVE-2025-5822 · published 25 June 2025

CVE-2025-5822: Autel maxicharger ac elite business c50 firmware incorrect authorization vulnerability

Autel · Maxicharger Ac Elite Business C50 Firmware

Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability. The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.

8.8 CVSS 3.1 High EPSS 0.41% · top 67.2% CWE-863 · Incorrect authorization
8.8CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability. The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-5822 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-5827Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all…EPSS 0.39%8.8CVE-2025-5830Autel maxicharger ac elite business c50 firmware heap-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows n…EPSS 0.39%8.8CVE-2024-23958Autel maxicharger ac elite business c50 firmware hard-coded credentials vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent att…EPSS 0.80%8.8CVE-2024-23957Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …EPSS 0.97%8.8CVE-2024-7795Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit…EPSS 0.53%8.0CVE-2024-23959Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability al…EPSS 0.82%8.0CVE-2024-23967Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…EPSS 0.91%7.5CVE-2025-6678Autel maxicharger ac elite business c50 firmware missing authentication for critical function vulnerabilityAutel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2025-5822), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.