// 2 CRITICAL · 5 ZERO-DAY · 5 CVE · 2 EXPLOIT IN THE LAST 24H
ZDI-26-436 (CVE-2026-13307, CVSS 7.8): Heap-based buffer overflow in the Autel MaxiCharger AC Elite Home allows arbitrary code execution via custom USB packets.

Methodology note: This article is based exclusively on the ZDI-26-436 advisory, a structured primary source published on July 15, 2026. The CVE-2026-13307 record remains in "reserved" status on CVE.org, with details not yet populated by the CNA.

On July 15, 2026, the Zero Day Initiative published advisory ZDI-26-436 detailing a vulnerability in the Autel MaxiCharger AC Elite Home residential charger. The flaw, tracked as CVE-2026-13307 with a CVSS score of 7.8, allows a physically present attacker to execute arbitrary code on the device via custom USB packets, with no authentication required. The discovery is part of the cluster of Autel vulnerabilities surfaced during Pwn2Own Automotive 2026.

Key Takeaways
  • CVE-2026-13307, CVSS 7.8: Heap-based buffer overflow in custom USB packet handling in the Autel MaxiCharger AC Elite Home.
  • Attack requires only physical presence: no authentication, no remote access needed.
  • Documented root cause: lack of user-supplied data length validation before copying into a fixed-size heap buffer.
  • 120 days of coordination between vendor notification (March 19, 2026) and public disclosure (July 15, 2026).
  • Patch status not explicitly stated in the advisory; verification with Autel required.

The Flaw: Documented Facts from the Advisory

According to advisory ZDI-26-436, "The specific flaw exists within the handling of custom USB packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer."

The advisory further specifies that "an attacker can leverage this vulnerability to execute code in the context of the device." The physical presence requirement is explicit: the attacker must be physically present to interact with the charger via USB.

"This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability." — ZDI Advisory ZDI-26-436

Analysis: The USB Vector and Device Context

The residential EV charger is typically installed in garages, driveways, or residential areas with controlled access. An attacker with physical access can interact via USB without bypassing any authentication controls.

The advisory does not document propagation chains to other network segments or specific physical consequences beyond code execution in the device context. The MaxiCharger AC Elite Home is an energy management node connected to the home electrical grid and, via Wi-Fi or Ethernet, to the home data network.

The ZDI advisory does not specify whether control of the compromised device could translate into manipulation of charging parameters or propagation to home network segments. These impact extensions are not documented in the primary source.

The Pwn2Own Automotive 2026 Context

The vulnerability falls within the Pwn2Own Automotive 2026 corpus, as indicated by the "(Pwn2Own)" prefix in the advisory and the ZDI publications list. The same list includes four other vulnerabilities for the same product: WebSockets integer underflow, NFC stack overflow, USB authentication bypass, and software update signature bypass.

This cluster of five vulnerabilities documents distinct attack surfaces in the device firmware. The advisory establishes no technical correlation between these vectors. The available data indicates an extended attack surface in the charger software, but does not support inferences about the overall security posture of the product or the EV charging sector.

What to Do Now

Advisory ZDI-26-436 contains no operational recommendations for users or administrators. The actions deducible from the documented facts are as follows:

  • Verify physical access: check who has access to the charger installation area. Garages, driveways, and residential areas must be accessible only to authorized users.
  • Contact Autel for patch status: the advisory does not declare patch availability or specific affected firmware versions. Verifying the status of a specific device requires direct contact with the vendor.
  • Monitor CVE-2026-13307: the record on CVE.org is in "reserved" status. Population by the CNA will provide additional details when available.
  • Inspect exposed USB ports: verify whether the device USB connector is physically accessible and whether undocumented mechanical barriers exist.

These actions are constrained by the limits of the dossier: no patch is confirmed available, no firmware version is indicated as immune, no verification tool is published.

Dossier Limits and Open Points

The dossier presents significant limits that condition operational reading. The identity of the researcher who discovered the vulnerability is not documented: the advisory credit field is empty.

The advisory itself does not specify affected firmware versions, making it impossible to determine whether a given device is vulnerable without direct vendor contact. The CVE-2026-13307 record on CVE.org is in "reserved" status, with details awaiting population.

The actual status of any patch released by Autel is not explicitly declared in the advisory, which mentions only "coordinated disclosure." No independent confirmation of the vulnerability exists outside the Pwn2Own context. Technical details of the exact USB payload or the buffer dimensions involved are not published.

Information was extracted from advisory ZDI-26-436 as the sole structured primary source available. Any updates will require verification against additional sources not yet published.

Sources: ZDI Advisory ZDI-26-436; ZDI Publications List; CVE-2026-13307; Trend Micro; Trend Micro Vision One

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. zerodayinitiative.com
  2. cve.org
  3. trendmicro.com