CyberICT

CVE-2026-8984

Autel · Published July 21, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

Affected Products

  • Maxicharger Single Charger Firmware <= 1.03.51

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H