Description
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Published: 2026-07-21
Score: 10 Critical
EPSS: 4.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware of Autel Maxi Charger Single V1.03.51 allows an unauthenticated attacker to inject arbitrary operating system commands via the /test endpoint on TCP port 9002. This OS command injection (CWE‑78) can lead to Remote Code Execution, compromising confidentiality, integrity, and availability of the device, its data, and any connected systems.

Affected Systems

The vulnerability affects the Autel Maxi Charger Single firmware, version 1.03.51. No other versions were enumerated.

Risk and Exploitability

The CVSS score of 10 indicates critical severity. The EPSS score of 4% suggests a non‑negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the /test endpoint is exposed on a public port and requires no authentication, the attack vector is likely network‑based. An attacker can directly send a crafted request to trigger the command injection.

Generated by OpenCVE AI on August 4, 2026 at 05:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the vulnerability, if an update is available.
  • If a firmware update cannot be applied, block or disable the /test endpoint or restrict access to TCP port 9002 to trusted networks.
  • Monitor network traffic for attempts to access /test or unusual command execution patterns and investigate any anomalies.

Generated by OpenCVE AI on August 4, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Title Unauthenticated Command Injection
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:37:37.583Z

Reserved: 2026-05-19T13:12:57.548Z

Link: CVE-2026-8985

cve-icon Vulnrichment

Updated: 2026-07-22T19:16:26.826Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')