Improper Firmware Signature Verification (CVE‑2026‑13305) Enables Arbitrary Code Execution on Autel MaxiCharger EV Chargers
What It Is — A flaw in the software‑update routine of Autel’s MaxiCharger AC Elite Home EV charger skips proper validation of the cryptographic signature on a supplied firmware image. An attacker who can physically connect to the device can load malicious code and gain full execution privileges.
Exploitability — No authentication is required; the attack vector is local/physical access. The vulnerability carries a CVSS v3.1 score of 6.4 (Moderate) with high confidentiality, integrity, and availability impact.
Affected Products — Autel MaxiCharger AC Elite Home (all firmware versions prior to V1.40.81).
Why It Matters for Compliance & Audit Readiness
- Illustrates a control‑mapping gap: SOC 2 CC6.1 (Change Management) requires documented, signed, and auditable software changes.
- Demonstrates the need for continuous evidence collection of firmware‑signing verification as part of a vendor‑risk program.
- Provides a concrete audit artifact (signed firmware hash, update logs) that can be presented to auditors to prove due diligence.
Recommended Actions
- Deploy the vendor‑provided fix (firmware V1.40.81) on every charger.
- Harden the update pipeline: enforce strong code‑signing, retain immutable logs of each firmware install, and restrict physical access.
- Map the remediation to SOC 2 change‑management controls and capture the patch‑deployment evidence in your Trust Center for audit readiness.
Source: Zero Day Initiative advisory