USB Authentication Bypass (CVE‑2026‑13306) in Autel MaxiCharger AC Elite Home EV Chargers
What It Is — A vulnerability in the USB interface of Autel’s MaxiCharger AC Elite Home EV charger that lets an attacker with physical proximity bypass authentication and invoke privileged functions. No credentials are required.
Exploitability — Physical‑access only; no remote exploit known. CVSS 4.3 (Low). Vendor‑provided fix in firmware V1.40.81.
Affected Products — Autel MaxiCharger AC Elite Home (all firmware versions prior to V1.40.81).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control criteria (CC6.1) require controls over both logical and physical entry points; a USB‑based bypass shows a gap in peripheral authentication.
- Maintaining up‑to‑date firmware and evidencing the version in a continuous‑monitoring system satisfies audit evidence requirements for change management.
- Demonstrates the need for documented policies that extend authentication requirements to all device interfaces, not just network ports.
Recommended Actions
- Inventory every deployed charger and confirm firmware ≥ V1.40.81; record version numbers as part of your audit artifact set.
- Amend your SOC 2 access‑control policy to mandate authentication for all physical interfaces (USB, serial, etc.) and require physical‑presence controls.
- Integrate automated firmware‑version checks into your continuous compliance monitoring platform to generate real‑time evidence of remediation.
Source: Zero Day Initiative Advisory