Critical Remote Code Execution in Autel MaxiCharger AC Elite Home (CVE‑2026‑13308) Threatens EV Charging Infrastructure
What It Is — A newly disclosed integer‑underflow flaw in the WebSocket handling of Autel’s MaxiCharger AC Elite Home EV charger allows unauthenticated remote attackers to execute arbitrary code on the device.
Exploitability — CVSS 8.1 (High). Network‑remote, no authentication required, no public PoC yet but the vulnerability is fully disclosed and exploitable.
Affected Products — Autel MaxiCharger AC Elite Home (firmware < V1.40.81).
Why It Matters for Compliance & Audit Readiness
- SOC 2 vendor‑management controls (CC6.1) require continuous monitoring of third‑party hardware patches; an unpatched charger breaks that control.
- Evidence of timely firmware updates and device‑level logging is essential to demonstrate due diligence during an audit.
- Enterprise buyers increasingly demand proof that critical IoT components in their supply chain are hardened, making vendor‑risk evidence a decisive factor in contract negotiations.
Recommended Actions
- Verify firmware version on all deployed MaxiCharger units; upgrade to V1.40.81 or later immediately.
- Map this RCE to SOC 2 CC6.1 (Vendor Management) and CC7.2 (System Operations) controls; capture patch‑deployment logs as audit evidence.
- Enable network segmentation and monitor WebSocket traffic for anomalous patterns to detect attempted exploitation.
- Incorporate the charger’s patch status into your continuous third‑party risk monitoring platform.