PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8989 Autel CVE debrief

The CVE record for CVE-2026-8989 was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, allowing unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data. The vulnerability has a high CVSS score of 8.6, indicating a high severity. Users of Autel Maxi Charger Single firmware through V1.03.51 should be aware of the potential risks associated with this vulnerability and take necessary precautions.

Vendor
Autel
Product
MaxiCharger Single
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Users of Autel Maxi Charger Single firmware through V1.03.51, operators of affected systems, and security teams responsible for vulnerability management should be aware of the potential risks associated with this vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

CVE-2026-8989 Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data. The vulnerability has a high CVSS score of 8.6, indicating a high severity. The affected product is Autel Maxi Charger Single firmware through V1.03.51. Defenders should focus on patching or mitigating this vulnerability due to its high CVSS score.

Defensive priority

High priority should be given to patching or mitigating this vulnerability due to its high CVSS score of 8.6.

Recommended defensive actions

  • Apply the latest firmware update for Autel Maxi Charger Single
  • Restrict physical access to the device
  • Monitor for suspicious activity
  • Consider implementing additional security controls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, but further analysis is needed to fully understand the impact. The vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, which permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data. Evidence is limited to CVE and NVD details, so defenders should verify exposed systems and review compensating controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.