Buffer overflow in MaxiCharger AC Elite Business 50A - CVE-2025-5828

 

Buffer overflow in MaxiCharger AC Elite Business 50A - CVE-2025-5828

Published: June 13, 2025


Vulnerability identifier: #VU111130
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-5828
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Autel Energy
Affected software:
MaxiCharger AC Elite Business 50A

Detailed vulnerability description

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the handling of USB frame packets. An attacker with physical access can trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2025-5828

Install updates from vendor's website.

Sources