From Pwn2Own Automotive: Taking Over the Autel Maxicharger
ID: 103991fb-e8d2-5c2e-95c0-7dd1764cd7ae
STIX ID: report--103991fb-e8d2-5c2e-95c0-7dd1764cd7ae
Feed Name: Zero Day Initiative (ZDI) Blog
Threat Score
Researchers at Pwn2Own 2024 discovered two remote vulnerabilities in Autel Maxicharger firmware v1.32 that enable remote code execution by overflowing a BLE client message buffer; Autel released firmware v1.35 to patch the issue by adding appropriate length checks, and the blog compares the vulnerable and patched binaries using Ghidra.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
