Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Improper Firmware Signature Verification (CVE-2026-13305) Enables Arbitrary Code Execution on Autel MaxiCharger EV Chargers

A flaw in Autel's MaxiCharger AC Elite Home firmware update process bypasses cryptographic signature checks, allowing physical attackers to run arbitrary code. For SOC 2‑ready organizations this highlights the need for documented change‑management and continuous evidence of signed software deployments.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Improper Firmware Signature Verification (CVE‑2026‑13305) Enables Arbitrary Code Execution on Autel MaxiCharger EV Chargers

What It Is — A flaw in the software‑update routine of Autel’s MaxiCharger AC Elite Home EV charger skips proper validation of the cryptographic signature on a supplied firmware image. An attacker who can physically connect to the device can load malicious code and gain full execution privileges.

Exploitability — No authentication is required; the attack vector is local/physical access. The vulnerability carries a CVSS v3.1 score of 6.4 (Moderate) with high confidentiality, integrity, and availability impact.

Affected Products — Autel MaxiCharger AC Elite Home (all firmware versions prior to V1.40.81).

Why It Matters for Compliance & Audit Readiness

  • Illustrates a control‑mapping gap: SOC 2 CC6.1 (Change Management) requires documented, signed, and auditable software changes.
  • Demonstrates the need for continuous evidence collection of firmware‑signing verification as part of a vendor‑risk program.
  • Provides a concrete audit artifact (signed firmware hash, update logs) that can be presented to auditors to prove due diligence.

Recommended Actions

  • Deploy the vendor‑provided fix (firmware V1.40.81) on every charger.
  • Harden the update pipeline: enforce strong code‑signing, retain immutable logs of each firmware install, and restrict physical access.
  • Map the remediation to SOC 2 change‑management controls and capture the patch‑deployment evidence in your Trust Center for audit readiness.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-433/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →