Description
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.
Published: 2026-07-21
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A hard‑coded authentication token is embedded in the firmware of the Autel MaxiCharger Single (v1.03.51). The token bypasses authorization checks for multiple management endpoints, allowing an attacker to trigger privileged functions without valid credentials. This weakness is classified as CWE-798, reflecting a hard‑coded or default authentication secret that can enable unauthorized actions.

Affected Systems

The affected product is the Autel MaxiCharger Single firmware version 1.03.51. No other vendors or products are currently reported to be impacted.

Risk and Exploitability

The CVSS score is 10, indicating the highest severity. The EPSS score is less than 1%, suggesting that exploitation is not broadly observed in the wild yet, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated or unauthenticated network connection to the device’s management interface, where an attacker supplies the special token value in an HTTP request or similar protocol to invoke privileged operations.

Generated by OpenCVE AI on July 30, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware update for the Autel MaxiCharger Single that removes the hard‑coded token
  • If an update is not yet available, restrict external network access to the device’s management endpoints using firewall rules or network segmentation
  • Disable or lock down any affected privileged functions that can be called with the hard‑coded token until a patch is applied

Generated by OpenCVE AI on July 30, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.
Title Backdoor Authentication Token
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:40:28.831Z

Reserved: 2026-05-19T13:12:55.680Z

Link: CVE-2026-8983

cve-icon Vulnrichment

Updated: 2026-07-22T19:25:07.994Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:30:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials