Impact
A hard‑coded authentication token is embedded in the firmware of the Autel MaxiCharger Single (v1.03.51). The token bypasses authorization checks for multiple management endpoints, allowing an attacker to trigger privileged functions without valid credentials. This weakness is classified as CWE-798, reflecting a hard‑coded or default authentication secret that can enable unauthorized actions.
Affected Systems
The affected product is the Autel MaxiCharger Single firmware version 1.03.51. No other vendors or products are currently reported to be impacted.
Risk and Exploitability
The CVSS score is 10, indicating the highest severity. The EPSS score is less than 1%, suggesting that exploitation is not broadly observed in the wild yet, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated or unauthenticated network connection to the device’s management interface, where an attacker supplies the special token value in an HTTP request or similar protocol to invoke privileged operations.
OpenCVE Enrichment