FR
live
vendor

Autel

6
vulnerabilities tracked
6
critical
21 July 2026
latest publication
cve

Vulnerability watch

idvulnerabilityseveritypublished
CVE-2026-8982Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.Autel Maxicharger Single Charger Firmware Critical CVSS 10 21/07 CVE-2026-8983Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.Autel Maxicharger Single Charger Firmware Critical CVSS 10 21/07 CVE-2026-8984Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.Autel Maxicharger Single Charger Firmware Critical CVSS 10 21/07 CVE-2026-8985Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.Autel Maxicharger Single Charger Firmware Critical CVSS 10 21/07 CVE-2026-8986Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.Autel Maxicharger Single Charger Firmware Critical CVSS 9.5 21/07 CVE-2026-8987Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.Autel Maxicharger Single Charger Firmware Critical CVSS 9.4 21/07

Type at least two characters.

navigate open esc dismiss