PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8984 Autel CVE debrief

CVE-2026-8984 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51, allowing unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges. This vulnerability has a CVSS score of 10 and a severity of CRITICAL.

Vendor
Autel
Product
MaxiCharger Single
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-13
Advisory published
2026-07-21
Advisory updated
2026-08-13

Who should care

Organizations using Autel Maxi Charger Single firmware through V1.03.51 should prioritize patching this vulnerability to prevent potential remote code execution attacks. Operators, platform administrators, vulnerability management teams, and security teams should review the affected scope and take necessary actions.

Technical summary

The vulnerability is caused by a service listening on TCP port 9002 in Autel Maxi Charger Single firmware through V1.03.51. An unauthenticated attacker can exploit this vulnerability by sending a crafted request to the /test endpoint, which can lead to the download, extraction, and execution of attacker-controlled files with root privileges. The affected product is Autel Maxi Charger Single firmware through V1.03.51.

Defensive priority

High

Recommended defensive actions

  • Apply the latest firmware update (V1.03.52 or later) to patch the vulnerability.
  • Restrict access to TCP port 9002 to only trusted networks or systems.
  • Monitor network traffic to detect potential exploitation attempts.
  • Implement additional security controls, such as intrusion detection and prevention systems.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-07-21T22:19:10.770Z and was last modified on 2026-07-22T20:17:09.170Z. The NVD entry is currently Awaiting Analysis. The vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, and defenders should verify the affected scope and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8984 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8984

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8984 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8984

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.