HomeIntelligenceBrief
VULNERABILITY BRIEF 🟢 Low Vulnerability

USB Authentication Bypass (CVE-2026-13306) in Autel MaxiCharger AC Elite Home EV Chargers

A low‑severity (CVSS 4.3) vulnerability in the USB port of Autel’s MaxiCharger AC Elite Home EV charger lets a physically present attacker bypass authentication. The issue is fixed in firmware V1.40.81, and the flaw underscores the need for SOC 2‑aligned access‑control policies that cover peripheral devices.

Verisq™ Intelligence · 📅 July 16, 2026 · 📰 zerodayinitiative.com
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

USB Authentication Bypass (CVE‑2026‑13306) in Autel MaxiCharger AC Elite Home EV Chargers

What It Is — A vulnerability in the USB interface of Autel’s MaxiCharger AC Elite Home EV charger that lets an attacker with physical proximity bypass authentication and invoke privileged functions. No credentials are required.

Exploitability — Physical‑access only; no remote exploit known. CVSS 4.3 (Low). Vendor‑provided fix in firmware V1.40.81.

Affected Products — Autel MaxiCharger AC Elite Home (all firmware versions prior to V1.40.81).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control criteria (CC6.1) require controls over both logical and physical entry points; a USB‑based bypass shows a gap in peripheral authentication.
  • Maintaining up‑to‑date firmware and evidencing the version in a continuous‑monitoring system satisfies audit evidence requirements for change management.
  • Demonstrates the need for documented policies that extend authentication requirements to all device interfaces, not just network ports.

Recommended Actions

  1. Inventory every deployed charger and confirm firmware ≥ V1.40.81; record version numbers as part of your audit artifact set.
  2. Amend your SOC 2 access‑control policy to mandate authentication for all physical interfaces (USB, serial, etc.) and require physical‑presence controls.
  3. Integrate automated firmware‑version checks into your continuous compliance monitoring platform to generate real‑time evidence of remediation.

Source: Zero Day Initiative Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-434/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →