High severity8.8NVD Advisory· Published Jun 25, 2025· Updated Jun 17, 2026
CVE-2025-5822
CVE-2025-5822
Description
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged authorization token in order to exploit this vulnerability.
The specific flaw exists within the implementation of the Autel Technician API. The issue results from incorrect authorization. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-26325.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 1.36.00
Patches
Vulnerability mechanics
References
1- www.zerodayinitiative.com/advisories/ZDI-25-340/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.