Heap‑Based USB Buffer Overflow (CVE‑2026‑13307) in Autel MaxiCharger AC Elite Home Enables Arbitrary Code Execution
What It Is — A heap‑based buffer overflow in the USB packet handling of Autel’s MaxiCharger AC Elite Home EV charger allows a physically present attacker to execute arbitrary code without authentication.
Exploitability — Requires local USB access; no public exploit code, but the flaw is trivial to trigger once a malicious USB device is connected. CVSS 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Products — Autel MaxiCharger AC Elite Home (firmware < V1.40.81).
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous vendor‑risk monitoring and documented firmware‑patch management to satisfy SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
- Provides concrete audit evidence that hardware assets are inventoried, their security posture is tracked, and remediation actions are recorded—critical for enterprises that must prove due diligence to customers and regulators.
Recommended Actions
- Inventory all deployed Autel MaxiCharger units and verify current firmware version.
- Apply firmware V1.40.81 or later immediately; retain the update package as evidence of remediation.
- Map the patch‑management activity to SOC 2 controls (CC6.1, CC7.1) and capture logs for continuous compliance reporting.
- Update your vendor‑risk profile for Autel, noting the vulnerability and remediation status.
Source: Zero Day Initiative advisory