Improper Authentication in MaxiCharger AC Elite Business 50A - #VU111125

 

Improper Authentication in MaxiCharger AC Elite Business 50A - #VU111125

Published: June 13, 2025


Vulnerability identifier: #VU111125
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests within the Pile API. A remote attacker can bypass authentication process and gain unauthorized access to sensitive information.


Affected software

MaxiCharger AC Elite Business 50A

Remediation

Install updates from vendor's website.

MaxiCharger AC Elite Business 50A - addressed in versions EU 1.56.51, US 1.39.51

External References

Related Security Bulletins