{"id": "CVE-2025-5822", "cveTags": [], "metrics": {"cvssMetricV30": [{"type": "Secondary", "source": "
[email protected]", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.1, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 4.2, "exploitabilityScore": 2.8}], "cvssMetricV31": [{"type": "Primary", "source": "
[email protected]", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2025-06-25T18:15:22.900", "references": [{"url": "https://www.zerodayinitiative.com/advisories/ZDI-25-340/", "tags": ["Third Party Advisory"], "source": "
[email protected]"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "
[email protected]", "description": [{"lang": "en", "value": "CWE-863"}]}], "descriptions": [{"lang": "en", "value": "Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325."}, {"lang": "es", "value": "Vulnerabilidad de escalada de privilegios de autorizaci\u00f3n incorrecta en la API de Autel MaxiCharger AC Wallbox Commercial Technician. Esta vulnerabilidad permite a atacantes remotos escalar privilegios en las instalaciones afectadas de las estaciones de carga Autel MaxiCharger AC Wallbox Commercial. Para explotar esta vulnerabilidad, un atacante debe obtener primero un token de autorizaci\u00f3n con privilegios bajos. La falla espec\u00edfica se encuentra en la implementaci\u00f3n de la API de Autel Technician. El problema se debe a una autorizaci\u00f3n incorrecta. Un atacante puede aprovechar esta vulnerabilidad para escalar privilegios a recursos que normalmente estar\u00edan protegidos del usuario. La vulnerabilidad era ZDI-CAN-26325."}], "lastModified": "2025-09-10T14:46:51.023", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "0C17A950-221C-41E3-9BE3-31736CE4516F", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "42F0DDFA-A1B9-4EC2-8F43-3261F9BCE814", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_ac_elite_business_c50:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5B2F9001-71B7-4B39-9114-FC54F4EAE9E7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_ac_pro_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "9471EA48-BD48-40AA-8FF7-28503D04D1F0", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_ac_pro_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "72FB45A6-E876-45A6-A39F-4E0B28620A71", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_ac_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "92CF3B40-B18F-4C4D-8A6C-68A8B1F288AE"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_ac_ultra_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "55C717AF-39F9-4080-AE56-7511E0F62F79", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_ac_ultra_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "7AFD91E7-E581-451B-AB15-099AA7A4F611", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_ac_ultra:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CDC6E5EB-C4D4-4488-B01B-C0E568FCA0D1"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_dc_compact_mobile_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "2C9AEB54-FFBC-4B24-AC7B-1B5F3CC762DF", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_dc_compact_mobile_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "BBFCD8D0-53E7-4B06-B763-36381E13DD26", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_dc_compact_mobile:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "52578631-C18D-4244-9377-AB787EDE08A1"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_dc_compact_pedestal_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "FED7B2BF-5D38-4393-9986-588407A3476D", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_dc_compact_pedestal_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "3244FD64-1714-4597-BA66-CC5FC8D514FF", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_dc_compact_pedestal:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "ED75BBD9-D889-49D3-95B0-EF6F15B65E10"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_dc_fast_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "264E7F9D-0603-43C9-B7A9-6A35EA8F0063", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_dc_fast_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "E5F4FE58-5AA6-45D0-AE48-959DA0CF53C8", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_dc_fast:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6C8B42B3-3F66-426F-8FFE-993FCAA12EB4"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_dc_hipower_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "E30E7592-29C4-4333-A02C-7468074BD104", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_dc_hipower_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "F9058C73-831E-48BF-AE9B-19AB33F10F14", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_dc_hipower:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EE5DF603-DBD2-4AFF-AE3D-946277C2C6C2"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_dh480_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "33F4A529-54C4-4EBC-871E-5E0C71859F69", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_dh480_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "62718E33-B591-49D4-8CC6-057D6254873A", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_dh480:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CAD62E93-8613-48DF-9C42-B12655FE1680"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:american_standard", "vulnerable": true, "matchCriteriaId": "372D3478-67AA-4D41-908C-5CFE6CAA25A8", "versionEndExcluding": "1.39.51"}, {"criteria": "cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:european_standard", "vulnerable": true, "matchCriteriaId": "8ED07235-5610-4E80-8940-6EB942CC648C", "versionEndExcluding": "1.56.51"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:autel:maxicharger_single_charger:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0E6B2074-D4A6-424F-B7C5-40A0FE5C17F8"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "
[email protected]"}