Input validation error in MaxiCharger AC Elite Business 50A - CVE-2025-5826

 

Input validation error in MaxiCharger AC Elite Business 50A - CVE-2025-5826

Published: June 13, 2025


Vulnerability identifier: #VU111128
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5826
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input within the ble_process_esp32_msg function. A remote attacker can pass specially crafted input to the application and execute AT commands in the context of the target device.


Affected software

MaxiCharger AC Elite Business 50A

How to mitigate CVE-2025-5826

Install updates from vendor's website.

MaxiCharger AC Elite Business 50A - addressed in versions EU 1.56.51, US 1.39.51

External References

Related Security Bulletins