Impact
The firmware of Autel Maxi Charger Single V1.03.51 allows an unauthenticated attacker to inject arbitrary operating system commands via the /test endpoint on TCP port 9002. This OS command injection (CWE‑78) can lead to Remote Code Execution, compromising confidentiality, integrity, and availability of the device, its data, and any connected systems.
Affected Systems
The vulnerability affects the Autel Maxi Charger Single firmware, version 1.03.51. No other versions were enumerated.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score of 4% suggests a non‑negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the /test endpoint is exposed on a public port and requires no authentication, the attack vector is likely network‑based. An attacker can directly send a crafted request to trigger the command injection.
OpenCVE Enrichment