CVE-2026-13308
Received Received - Intake

WebSocket Integer Underflow in Autel MaxiCharger AC Elite Home

Vulnerability report for CVE-2026-13308, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: Zero Day Initiative

Description

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29113.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
autel maxicharger_ac_elite_home *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer underflow in the WebSocket handling of Autel MaxiCharger AC Elite Home EV chargers. It allows remote attackers to execute arbitrary code without authentication by exploiting improper validation of user-supplied data in the OCPP service.

Detection Guidance

This vulnerability involves an integer underflow in WebSocket message handling for the OCPP service in Autel MaxiCharger AC Elite Home EV chargers. Detection requires network monitoring for unusual WebSocket traffic or unauthorized code execution attempts targeting these devices. Check logs for unexpected connections or commands to the OCPP service port.

Impact Analysis

An attacker could gain control of your Autel MaxiCharger AC Elite Home EV charger, potentially leading to unauthorized access, data theft, or disruption of charging services. Since authentication is not required, any exposed device is at risk.

Mitigation Strategies

Immediate mitigation includes isolating affected chargers from untrusted networks, disabling unnecessary services, and applying firmware updates if available. Ensure the OCPP service is not exposed to the internet and restrict access to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13308. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart