HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Improper Firmware Signature Verification (CVE-2026-13305) Enables Arbitrary Code Execution on Autel MaxiCharger EV Chargers

A flaw in Autel's MaxiCharger AC Elite Home firmware update process bypasses cryptographic signature checks, allowing physical attackers to run arbitrary code. For SOC 2‑ready organizations this highlights the need for documented change‑management and continuous evidence of signed software deployments.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Improper Firmware Signature Verification (CVE‑2026‑13305) Enables Arbitrary Code Execution on Autel MaxiCharger EV Chargers

What It Is — A flaw in the software‑update routine of Autel’s MaxiCharger AC Elite Home EV charger skips proper validation of the cryptographic signature on a supplied firmware image. An attacker who can physically connect to the device can load malicious code and gain full execution privileges.

Exploitability — No authentication is required; the attack vector is local/physical access. The vulnerability carries a CVSS v3.1 score of 6.4 (Moderate) with high confidentiality, integrity, and availability impact.

Affected Products — Autel MaxiCharger AC Elite Home (all firmware versions prior to V1.40.81).

Why It Matters for Compliance & Audit Readiness

  • Illustrates a control‑mapping gap: SOC 2 CC6.1 (Change Management) requires documented, signed, and auditable software changes.
  • Demonstrates the need for continuous evidence collection of firmware‑signing verification as part of a vendor‑risk program.
  • Provides a concrete audit artifact (signed firmware hash, update logs) that can be presented to auditors to prove due diligence.

Recommended Actions

  • Deploy the vendor‑provided fix (firmware V1.40.81) on every charger.
  • Harden the update pipeline: enforce strong code‑signing, retain immutable logs of each firmware install, and restrict physical access.
  • Map the remediation to SOC 2 change‑management controls and capture the patch‑deployment evidence in your Trust Center for audit readiness.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-433/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →