CVE-2025-5825
Autel Maxicharger Ac Elite Business C50 Firmware ≤ 1.39.51
Raw vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2025-5825 is a high-severity Security Version Number Mutable to Older Versions (CWE-1328) vulnerability in Autel Maxicharger Ac Elite Business C50 Firmware. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Downgrade Attack (T1689); ranked at the 14th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SC-51 (Hardware-based Protection) and SI-7 (Software, Firmware, and Information Integrity) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-28667
Vulnerability Data
Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair…
more
a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the firmware update process. The issue results from the lack of proper validation of a firmware image before using it to perform an upgrade. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-26354.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Hardware-enforced write protection directly stops unauthorized mutation of a security version number to older values.
Firmware integrity verification can discover that a version rollback has occurred after the fact.
Enforcing access restrictions on configuration changes can block unauthorized writes to a mutable security version register.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Pre-acquisition assessment of hardware authenticity/integrity directly prevents purchase of chips whose security version numbers can be rolled back.
Hardened baselines and configuration management can enforce immutable version checks or secure-boot policies that mitigate rollback.
Hardware lacking immutable version-number protection can be identified and replaced as part of risk-based hardware maintenance.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Controlled software installation procedures can block unauthorized or older firmware versions from being loaded.
Secure SDLC practices can embed anti-rollback mechanisms during hardware/firmware design.
Secure architecture principles can mandate hardware-enforced version counters or fuses.
Change-management processes can require cryptographic verification of firmware versions before deployment.
Configuration management can enforce immutable or version-locked firmware images, limiting rollback risk.