PatchSiren

Autel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Autel CVE published 2026-07-21

CVE-2026-8989

The CVE record for CVE-2026-8989 was published on 2026-07-21T22:19:11.387Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects Autel Maxi Charger Single firmware through V1.03.51, allowing unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in [truncated]

HIGH Autel CVE published 2026-07-21

CVE-2026-8988

The CVE record for CVE-2026-8988 was published on 2026-07-21T22:19:11.270Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. CVE-2026-8988 is a vulnerability in Autel Maxi Charger Single firmware through V1.03.51 that exposes an accessible UART interface. This allows an attacker with physical access to interrupt the boot process and access the U-Boot bootloader, potential [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8987

CVE-2026-8987 describes a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51. A heap-based buffer overflow exists in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution. The CVSS score is 9.4, indicating a critical severity. Organizations using Au [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8986

CVE-2026-8986 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station. This vulnerability has a CVSS score of 9.5 and is classified as CRITICAL. The vulnerability affects Autel Maxi Ch [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8985

CVE-2026-8985 is an OS command injection vulnerability in Autel Maxi Charger Single firmware through V1.03.51. The vulnerability is located in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands. This vulnerability has a CVSS score of 10, indicating a critical severity. Organizations should pr [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8984

CVE-2026-8984 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51, allowing unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges. This vulnerability has a CVSS score of 10 and a severity of CRITICAL.

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8983

CVE-2026-8983 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication. This vulnerability has a CVSS score of 10 and is classified as CRITICAL. Users should verify their systems are update [truncated]

CRITICAL Autel CVE published 2026-07-21

CVE-2026-8982

CVE-2026-8982 is a critical vulnerability in Autel Maxi Charger Single firmware through V1.03.51. Two undocumented privileged accounts exist with vendor-defined password derivation mechanisms based on device-specific values. This allows an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges. Organizations should priori [truncated]