{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T00:19:49.414","vulnerabilities":[{"cve":{"id":"CVE-2025-5824","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2025-06-25T18:15:23.173","lastModified":"2025-09-10T14:46:54.780","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Commercial. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of bluetooth pairing requests. The issue results from insufficient validation of the origin of commands. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26353."},{"lang":"es","value":"Vulnerabilidad de omisión de autenticación por error de validación de origen en Autel MaxiCharger AC Wallbox Commercial. Esta vulnerabilidad permite a atacantes adyacentes a la red omitir la autenticación en las instalaciones afectadas de Autel MaxiCharger AC Wallbox Commercial. Para explotar esta vulnerabilidad, un atacante debe primero emparejar un dispositivo Bluetooth malicioso con el sistema objetivo. La falla específica se encuentra en la gestión de solicitudes de emparejamiento Bluetooth. El problema se debe a una validación insuficiente del origen de los comandos. Un atacante puede aprovechar esta vulnerabilidad para omitir la autenticación en el sistema. Anteriormente, se conocía como ZDI-CAN-26353."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.4}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"0C17A950-221C-41E3-9BE3-31736CE4516F"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_ac_elite_business_c50_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"42F0DDFA-A1B9-4EC2-8F43-3261F9BCE814"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_ac_elite_business_c50:-:*:*:*:*:*:*:*","matchCriteriaId":"5B2F9001-71B7-4B39-9114-FC54F4EAE9E7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_ac_pro_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"9471EA48-BD48-40AA-8FF7-28503D04D1F0"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_ac_pro_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"72FB45A6-E876-45A6-A39F-4E0B28620A71"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_ac_pro:-:*:*:*:*:*:*:*","matchCriteriaId":"92CF3B40-B18F-4C4D-8A6C-68A8B1F288AE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_ac_ultra_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"55C717AF-39F9-4080-AE56-7511E0F62F79"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_ac_ultra_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"7AFD91E7-E581-451B-AB15-099AA7A4F611"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_ac_ultra:-:*:*:*:*:*:*:*","matchCriteriaId":"CDC6E5EB-C4D4-4488-B01B-C0E568FCA0D1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_compact_mobile_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"2C9AEB54-FFBC-4B24-AC7B-1B5F3CC762DF"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_compact_mobile_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"BBFCD8D0-53E7-4B06-B763-36381E13DD26"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_dc_compact_mobile:-:*:*:*:*:*:*:*","matchCriteriaId":"52578631-C18D-4244-9377-AB787EDE08A1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_compact_pedestal_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"FED7B2BF-5D38-4393-9986-588407A3476D"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_compact_pedestal_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"3244FD64-1714-4597-BA66-CC5FC8D514FF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_dc_compact_pedestal:-:*:*:*:*:*:*:*","matchCriteriaId":"ED75BBD9-D889-49D3-95B0-EF6F15B65E10"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_fast_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"264E7F9D-0603-43C9-B7A9-6A35EA8F0063"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_fast_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"E5F4FE58-5AA6-45D0-AE48-959DA0CF53C8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_dc_fast:-:*:*:*:*:*:*:*","matchCriteriaId":"6C8B42B3-3F66-426F-8FFE-993FCAA12EB4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_hipower_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"E30E7592-29C4-4333-A02C-7468074BD104"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dc_hipower_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"F9058C73-831E-48BF-AE9B-19AB33F10F14"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_dc_hipower:-:*:*:*:*:*:*:*","matchCriteriaId":"EE5DF603-DBD2-4AFF-AE3D-946277C2C6C2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dh480_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"33F4A529-54C4-4EBC-871E-5E0C71859F69"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_dh480_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"62718E33-B591-49D4-8CC6-057D6254873A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_dh480:-:*:*:*:*:*:*:*","matchCriteriaId":"CAD62E93-8613-48DF-9C42-B12655FE1680"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:american_standard","versionEndExcluding":"1.39.51","matchCriteriaId":"372D3478-67AA-4D41-908C-5CFE6CAA25A8"},{"vulnerable":true,"criteria":"cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:european_standard","versionEndExcluding":"1.56.51","matchCriteriaId":"8ED07235-5610-4E80-8940-6EB942CC648C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:autel:maxicharger_single_charger:-:*:*:*:*:*:*:*","matchCriteriaId":"0E6B2074-D4A6-424F-B7C5-40A0FE5C17F8"}]}]}],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-343/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]}]}}]}