HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in Autel MaxiCharger AC Elite Home (CVE‑2026‑13308) Threatens EV Charging Infrastructure

A remote integer‑underflow flaw in Autel’s MaxiCharger AC Elite Home EV charger (CVE‑2026‑13308) enables unauthenticated code execution. For SOC 2‑ready organizations, the issue underscores the need for continuous third‑party device monitoring and audit‑ready patch evidence.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in Autel MaxiCharger AC Elite Home (CVE‑2026‑13308) Threatens EV Charging Infrastructure

What It Is — A newly disclosed integer‑underflow flaw in the WebSocket handling of Autel’s MaxiCharger AC Elite Home EV charger allows unauthenticated remote attackers to execute arbitrary code on the device.

Exploitability — CVSS 8.1 (High). Network‑remote, no authentication required, no public PoC yet but the vulnerability is fully disclosed and exploitable.

Affected Products — Autel MaxiCharger AC Elite Home (firmware < V1.40.81).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 vendor‑management controls (CC6.1) require continuous monitoring of third‑party hardware patches; an unpatched charger breaks that control.
  • Evidence of timely firmware updates and device‑level logging is essential to demonstrate due diligence during an audit.
  • Enterprise buyers increasingly demand proof that critical IoT components in their supply chain are hardened, making vendor‑risk evidence a decisive factor in contract negotiations.

Recommended Actions

  • Verify firmware version on all deployed MaxiCharger units; upgrade to V1.40.81 or later immediately.
  • Map this RCE to SOC 2 CC6.1 (Vendor Management) and CC7.2 (System Operations) controls; capture patch‑deployment logs as audit evidence.
  • Enable network segmentation and monitor WebSocket traffic for anomalous patterns to detect attempted exploitation.
  • Incorporate the charger’s patch status into your continuous third‑party risk monitoring platform.

Source: Zero Day Initiative Advisory – ZDI‑26‑437

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-437/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →