Input validation error in MaxiCharger AC Elite Business 50A - CVE-2025-5826
Published: June 13, 2025
Vulnerability identifier: #VU111128
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5826
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input within the ble_process_esp32_msg function. A remote attacker can pass specially crafted input to the application and execute AT commands in the context of the target device.
Affected software
MaxiCharger AC Elite Business 50A
How to mitigate CVE-2025-5826
Install updates from vendor's website.
MaxiCharger AC Elite Business 50A - addressed in versions EU 1.56.51, US 1.39.51