Description
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
Published: 2026-07-21
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted request to the /test endpoint on the Autel Maxi Charger Single’s service listening on TCP port 9002 allows an attacker to cause the device to download, extract and execute attacker‑controlled files with root privileges. The vulnerability is a code‑injection flaw mapped to CWE‑94 and results in full remote code execution without requiring authentication.

Affected Systems

Units of the Autel Maxi Charger Single firmware version V1.03.51 or earlier are vulnerable. Devices exposing TCP port 9002 to the network are at risk. No other firmware versions are mentioned in the advisory.

Risk and Exploitability

The CVSS base score of 10.0 marks the flaw as critical, while the EPSS score of less than 1% indicates a low but non‑zero exploitation probability in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attacks require network access to the device’s management service; an attacker can trigger the flaw remotely, leading to compromise with root privilege.

Generated by OpenCVE AI on August 3, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that contains the RCE fix.
  • Restrict or block access to TCP port 9002 from untrusted networks using firewall rules or network segmentation.
  • Configure the device to log requests to the /test endpoint and review logs for unexpected downloads or execution attempts.

Generated by OpenCVE AI on August 3, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
Title Unauthenticated RCE
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:38:02.292Z

Reserved: 2026-05-19T13:12:56.651Z

Link: CVE-2026-8984

cve-icon Vulnrichment

Updated: 2026-07-22T19:16:00.938Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:30:16Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')