HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Physical NFC Buffer Overflow (CVE-2026-13309) Enables Arbitrary Code Execution on Autel MaxiCharger EV Chargers

A stack‑based buffer overflow in the NFC interface of Autel’s MaxiCharger AC Elite Home EV charger allows an unauthenticated, physically proximate attacker to execute arbitrary code. For SOC 2‑ready organizations, the flaw underscores the need for documented physical‑access controls and continuous firmware‑version evidence.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Physical NFC Stack‑Based Buffer Overflow (CVE‑2026‑13309) in Autel MaxiCharger AC Elite Home EV Charger

What It Is — A stack‑based buffer overflow in the NFC card‑response handling of Autel’s MaxiCharger AC Elite Home EV charger. An attacker with physical proximity can present a malicious NFC card and trigger arbitrary code execution without authentication.

Exploitability — Requires physical proximity to the charger’s NFC reader; no network access needed. Demonstrated by the Pwn2Own team; no public PoC released. CVSS 6.8 (High) – AV:P, AC:L, PR:N, UI:N, C:H, I:H, A:H.

Affected Products — Autel MaxiCharger AC Elite Home (firmware < V1.40.81). Fixed in firmware V1.40.81.

Why It Matters for Compliance & Audit Readiness

  • Highlights a physical‑access control gap that must be covered by SOC 2 CC6.1 (Change Management) and CC7.1 (Physical & Environmental Security).
  • Continuous evidence of firmware version and patch status is essential to satisfy audit queries on vulnerability management.
  • Organizations that deploy third‑party EV chargers in corporate facilities need documented vendor‑risk assessments and proof of remediation.

Recommended Actions

  • Upgrade all affected chargers to firmware V1.40.81 immediately.
  • Record firmware version in your asset inventory and map to SOC 2 Change Management controls.
  • Incorporate NFC‑port physical‑access restrictions into facility‑security policies and capture evidence.
  • Add the vendor to your third‑party risk register and schedule periodic compliance checks.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-435/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →