HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Heap‑Based USB Buffer Overflow (CVE‑2026‑13307) in Autel MaxiCharger AC Elite Home Enables Arbitrary Code Execution

A heap‑based USB buffer overflow in Autel’s MaxiCharger AC Elite Home EV charger (CVE‑2026‑13307) allows unauthenticated code execution via a malicious USB device. For SOC 2‑ready organizations, the flaw underscores the importance of continuous firmware‑patch tracking and vendor‑risk evidence.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Heap‑Based USB Buffer Overflow (CVE‑2026‑13307) in Autel MaxiCharger AC Elite Home Enables Arbitrary Code Execution

What It Is — A heap‑based buffer overflow in the USB packet handling of Autel’s MaxiCharger AC Elite Home EV charger allows a physically present attacker to execute arbitrary code without authentication.

Exploitability — Requires local USB access; no public exploit code, but the flaw is trivial to trigger once a malicious USB device is connected. CVSS 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products — Autel MaxiCharger AC Elite Home (firmware < V1.40.81).

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous vendor‑risk monitoring and documented firmware‑patch management to satisfy SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
  • Provides concrete audit evidence that hardware assets are inventoried, their security posture is tracked, and remediation actions are recorded—critical for enterprises that must prove due diligence to customers and regulators.

Recommended Actions

  • Inventory all deployed Autel MaxiCharger units and verify current firmware version.
  • Apply firmware V1.40.81 or later immediately; retain the update package as evidence of remediation.
  • Map the patch‑management activity to SOC 2 controls (CC6.1, CC7.1) and capture logs for continuous compliance reporting.
  • Update your vendor‑risk profile for Autel, noting the vulnerability and remediation status.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-436/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →