Impact
The vulnerability consists of two undocumented privileged accounts embedded in the Autel Maxi Charger Single firmware up to version V1.03.51. These accounts are protected by a vendor‑defined password derivation algorithm that uses device‑specific data. An attacker who understands the algorithm and has the required inputs can compute a valid password and authenticate to the device’s web management interface with administrative privileges. This could allow the attacker to alter device configuration settings.
Affected Systems
Autel’s Maxi Charger Single vehicles deployed with firmware versions through V1.03.51 are impacted. The flaw exists solely in the firmware code that implements the web interface; the status of firmware releases beyond V1.03.51 is not stated in the CVE data.
Risk and Exploitability
The CVSS score of 10 indicates a severe impact due to administrative privilege escalation. The EPSS score of less than 1% shows that actual exploitation is expected to be rare, likely requiring reverse‑engineering of the password derivation algorithm and network access to the device’s web interface. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network‑level access to the web interface and knowledge of the password derivation routine to exploit this flaw, which limits exploitation to environments where the device is exposed and the algorithm has been reverse‑engineered.
OpenCVE Enrichment