← Vulnerability feed

Vulnerability record · CVE-2025-6678 · published 25 June 2025

CVE-2025-6678: Autel maxicharger ac elite business c50 firmware missing authentication for critical function vulnerability

Autel · Maxicharger Ac Elite Business C50 Firmware

Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Pile API. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose credentials, leading to further compromise. Was ZDI-CAN-26352.

7.5 CVSS 3.0 High EPSS 0.48% · top 61.1% CWE-306 · Missing authentication for critical function
7.5CVSS 3.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Pile API. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose credentials, leading to further compromise. Was ZDI-CAN-26352.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-5827Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all…EPSS 0.39%8.8CVE-2025-5830Autel maxicharger ac elite business c50 firmware heap-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows n…EPSS 0.39%8.8CVE-2025-5822Autel maxicharger ac elite business c50 firmware incorrect authorization vulnerabilityAutel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a…EPSS 0.41%8.8CVE-2024-23958Autel maxicharger ac elite business c50 firmware hard-coded credentials vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent att…EPSS 0.80%8.8CVE-2024-23957Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …EPSS 0.97%8.8CVE-2024-7795Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit…EPSS 0.53%8.0CVE-2024-23959Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability al…EPSS 0.82%8.0CVE-2024-23967Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…EPSS 0.91%

Source: NIST National Vulnerability Database (record CVE-2025-6678), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.