PatchSiren cyber security CVE debrief
CVE-2026-8989 Autel CVE debrief
The CVE record for CVE-2026-8989 was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, allowing unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data. The vulnerability has a high CVSS score of 8.6, indicating a high severity. Users of Autel Maxi Charger Single firmware through V1.03.51 should be aware of the potential risks associated with this vulnerability and take necessary precautions.
- Vendor
- Autel
- Product
- MaxiCharger Single
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of Autel Maxi Charger Single firmware through V1.03.51, operators of affected systems, and security teams responsible for vulnerability management should be aware of the potential risks associated with this vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
CVE-2026-8989 Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data. The vulnerability has a high CVSS score of 8.6, indicating a high severity. The affected product is Autel Maxi Charger Single firmware through V1.03.51. Defenders should focus on patching or mitigating this vulnerability due to its high CVSS score.
Defensive priority
High priority should be given to patching or mitigating this vulnerability due to its high CVSS score of 8.6.
Recommended defensive actions
- Apply the latest firmware update for Autel Maxi Charger Single
- Restrict physical access to the device
- Monitor for suspicious activity
- Consider implementing additional security controls
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, but further analysis is needed to fully understand the impact. The vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, which permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data. Evidence is limited to CVE and NVD details, so defenders should verify exposed systems and review compensating controls.
Official resources
-
CVE-2026-8989 CVE record
CVE.org
-
CVE-2026-8989 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.