8.6
CVE-2026-8988
- EPSS 0.22%
- Veröffentlicht 21.07.2026 21:21:50
- Zuletzt bearbeitet 13.08.2026 11:50:56
- CVE-Watchlists
- Unerledigt
Access to Bootloader
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autel ≫ Maxicharger Single Charger Firmware Version <= 1.03.51
Autel ≫ Maxicharger Single Charger Firmware Version <= 1.03.51
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| office@cyberdanube.com | 8.6 | 0 | 0 |
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-1191 On-Chip Debug and Test Interface With Improper Access Control
The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.
https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/