CVE-2026-8984
Autel · Published July 21, 2026
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
Affected Products
- Maxicharger Single Charger Firmware <= 1.03.51
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H