8.8

CVE-2025-5822

Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability.

The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AutelMaxicharger Ac Pro Firmware Version < 1.39.51
   AutelMaxicharger Ac Pro Version-
AutelMaxicharger Ac Pro Firmware Version < 1.56.51
   AutelMaxicharger Ac Pro Version-
AutelMaxicharger Ac Ultra Firmware Version < 1.39.51
   AutelMaxicharger Ac Ultra Version-
AutelMaxicharger Ac Ultra Firmware Version < 1.56.51
   AutelMaxicharger Ac Ultra Version-
AutelMaxicharger Dc Fast Firmware Version < 1.39.51
   AutelMaxicharger Dc Fast Version-
AutelMaxicharger Dc Fast Firmware Version < 1.56.51
   AutelMaxicharger Dc Fast Version-
AutelMaxicharger Dc Hipower Firmware Version < 1.39.51
   AutelMaxicharger Dc Hipower Version-
AutelMaxicharger Dc Hipower Firmware Version < 1.56.51
   AutelMaxicharger Dc Hipower Version-
AutelMaxicharger Dh480 Firmware Version < 1.39.51
   AutelMaxicharger Dh480 Version-
AutelMaxicharger Dh480 Firmware Version < 1.56.51
   AutelMaxicharger Dh480 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.142
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
zdi-disclosures@trendmicro.com 7.1 2.8 4.2
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.