Physical NFC Stack‑Based Buffer Overflow (CVE‑2026‑13309) in Autel MaxiCharger AC Elite Home EV Charger
What It Is — A stack‑based buffer overflow in the NFC card‑response handling of Autel’s MaxiCharger AC Elite Home EV charger. An attacker with physical proximity can present a malicious NFC card and trigger arbitrary code execution without authentication.
Exploitability — Requires physical proximity to the charger’s NFC reader; no network access needed. Demonstrated by the Pwn2Own team; no public PoC released. CVSS 6.8 (High) – AV:P, AC:L, PR:N, UI:N, C:H, I:H, A:H.
Affected Products — Autel MaxiCharger AC Elite Home (firmware < V1.40.81). Fixed in firmware V1.40.81.
Why It Matters for Compliance & Audit Readiness
- Highlights a physical‑access control gap that must be covered by SOC 2 CC6.1 (Change Management) and CC7.1 (Physical & Environmental Security).
- Continuous evidence of firmware version and patch status is essential to satisfy audit queries on vulnerability management.
- Organizations that deploy third‑party EV chargers in corporate facilities need documented vendor‑risk assessments and proof of remediation.
Recommended Actions
- Upgrade all affected chargers to firmware V1.40.81 immediately.
- Record firmware version in your asset inventory and map to SOC 2 Change Management controls.
- Incorporate NFC‑port physical‑access restrictions into facility‑security policies and capture evidence.
- Add the vendor to your third‑party risk register and schedule periodic compliance checks.
Source: Zero Day Initiative advisory