logo

Reviewing the Attack Surface of the Autel MaxiCharger: Part Two

ID: 38363eee-6404-51e9-87f4-a647352ad92d

STIX ID: report--38363eee-6404-51e9-87f4-a647352ad92d

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
45/100

Date Published: 2025-01-16

Date Updated: 2026-05-01

Author: Connor Ford

...
...

This post outlines the attack surface of the Autel MaxiCharger EV charger based on reverse engineering and manual review. It lists software versions for charger modules and mobile apps, describes app features (scheduling, load balancing, Wi‑Fi provisioning, forced firmware updates, OCPP server configuration) that could be abused, and notes anti‑reversing behavior observed in the Android app.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.