The CVE record for CVE-2026-8989 was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, allowing unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in [truncated]
CVE-2026-8987 describes a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51. A heap-based buffer overflow exists in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution. The CVSS score is 9.4, indicating a critical severity. Organizations using Au [truncated]
CVE-2026-8984 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51, allowing unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges. This vulnerability has a CVSS score of 10 and a severity of CRITICAL.
CVE-2026-8983 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication. This vulnerability has a CVSS score of 10 and is classified as CRITICAL. Users should verify their systems are update [truncated]
CVE-2026-8982 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51. Two undocumented privileged accounts exist with vendor-defined password derivation mechanisms based on device-specific values. This allows an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges. Organizations should priori [truncated]