logo

From Pwn2Own Automotive: More Autel Maxicharger Vulnerabilities

ID: fc1d5bbe-029a-53f1-9fdc-bb353b0427ca

STIX ID: report--fc1d5bbe-029a-53f1-9fdc-bb353b0427ca

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
65/100

Date Published: 2024-10-03

Date Updated: 2026-05-01

Author: Connor Ford

...
...

This report describes two firmware vulnerabilities in Autel EV charger software: an unsafe base64_decode implementation that lacks output-buffer length checking and a stack buffer overflow (CVE-2024-23957) in the Dynamic Load Balancing protocol when decoding oversized hex-encoded AES keys; both can cause memory corruption and potentially enable exploitation, and the report recommends API-level fixes or using Mbed TLS functions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.