PatchSiren

Autel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Autel CVE published 2026-07-21

CVE-2026-8989

The CVE record for CVE-2026-8989 was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, allowing unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8987

CVE-2026-8987 describes a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51. A heap-based buffer overflow exists in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution. The CVSS score is 9.4, indicating a critical severity. Organizations using Au [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8984

CVE-2026-8984 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51, allowing unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges. This vulnerability has a CVSS score of 10 and a severity of CRITICAL.

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8983

CVE-2026-8983 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication. This vulnerability has a CVSS score of 10 and is classified as CRITICAL. Users should verify their systems are update [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8982

CVE-2026-8982 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51. Two undocumented privileged accounts exist with vendor-defined password derivation mechanisms based on device-specific values. This allows an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges. Organizations should priori [truncated]