Reviewing the Attack Surface of the Autel MaxiCharger: Part One
ID: 863db750-aafd-5e2f-851c-a00fce26640a
STIX ID: report--863db750-aafd-5e2f-851c-a00fce26640a
Feed Name: Zero Day Initiative (ZDI) Blog
A hardware teardown of an Autel charger outlines components and interfaces including a GD32 MCU, a Winbond W25Q128JV SPI flash, an ESP32-WROOM-32D module providing Wi‑Fi/Bluetooth, RJ45 Ethernet, an undocumented USB‑C port, and a stacked 4G module with SIM. UART output from the GD32 at 921600 bps logs AT commands to the ESP32 and the string 'UART_WIFI_BT', suggesting the ESP32 handles Bluetooth functionality, potentially rendering the Barrot module redundant; an ESP32 UART at 115200 bps shows standard boot logs. The report also references prior research demonstrating readout-protection bypasses for similar MCUs but does not present a specific security incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
