Impact
A crafted OCPP GetDiagnostics request can trigger OS command injection in the Autel Maxi Charger Single firmware V1.03.51. The vulnerability, classified as CWE‑78, allows a malicious or compromised OCPP server to supply a diagnostics URL that is executed on the charging station, giving an attacker arbitrary command execution capability and potentially full control of the device.
Affected Systems
Autel Maxi Charger Single devices running firmware version 1.03.51 are impacted. No other product or version information is listed.
Risk and Exploitability
The CVSS v3.1 score of 9.5 indicates critical severity. The EPSS score of 1% indicates a low but non‑zero probability of exploitation in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers can exploit the flaw by acting as a rogue OCPP server or by compromising an existing server, after which they send a malicious GetDiagnostics command over the network. Successful exploitation leads to arbitrary command execution without requiring local user interaction or elevated privileges on the device.
OpenCVE Enrichment