Impact
A crafted request to the /test endpoint on the Autel Maxi Charger Single’s service listening on TCP port 9002 allows an attacker to cause the device to download, extract and execute attacker‑controlled files with root privileges. The vulnerability is a code‑injection flaw mapped to CWE‑94 and results in full remote code execution without requiring authentication.
Affected Systems
Units of the Autel Maxi Charger Single firmware version V1.03.51 or earlier are vulnerable. Devices exposing TCP port 9002 to the network are at risk. No other firmware versions are mentioned in the advisory.
Risk and Exploitability
The CVSS base score of 10.0 marks the flaw as critical, while the EPSS score of less than 1% indicates a low but non‑zero exploitation probability in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attacks require network access to the device’s management service; an attacker can trigger the flaw remotely, leading to compromise with root privilege.
OpenCVE Enrichment