CVE-2026-8989
- EPSS 0.28%
- Veröffentlicht 21.07.2026 21:24:28
- Zuletzt bearbeitet 13.08.2026 13:19:12
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract ...
CVE-2026-8988
- EPSS 0.22%
- Veröffentlicht 21.07.2026 21:21:50
- Zuletzt bearbeitet 13.08.2026 11:50:56
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file sys...
CVE-2026-8987
- EPSS 0.51%
- Veröffentlicht 21.07.2026 21:18:32
- Zuletzt bearbeitet 13.08.2026 12:54:37
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentia...
CVE-2026-8986
- EPSS 2.29%
- Veröffentlicht 21.07.2026 21:14:26
- Zuletzt bearbeitet 13.08.2026 13:28:19
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command exec...
CVE-2026-8985
- EPSS 6.6%
- Veröffentlicht 21.07.2026 21:11:25
- Zuletzt bearbeitet 13.08.2026 13:32:45
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system ...
CVE-2026-8984
- EPSS 0.77%
- Veröffentlicht 21.07.2026 21:08:49
- Zuletzt bearbeitet 13.08.2026 13:27:12
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-contr...
CVE-2026-8983
- EPSS 0.43%
- Veröffentlicht 21.07.2026 21:03:22
- Zuletzt bearbeitet 12.08.2026 15:21:48
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality wit...
CVE-2026-8982
- EPSS 0.38%
- Veröffentlicht 21.07.2026 21:01:02
- Zuletzt bearbeitet 12.08.2026 15:23:46
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm an...
CVE-2025-6678
- EPSS 0.42%
- Veröffentlicht 25.06.2025 18:15:25
- Zuletzt bearbeitet 10.09.2025 14:46:24
Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial...
CVE-2025-5830
- EPSS 0.34%
- Veröffentlicht 25.06.2025 18:15:23
- Zuletzt bearbeitet 10.09.2025 14:46:36
Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC...