Description
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.
Published: 2026-07-21
Score: 9.5 Critical
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted OCPP GetDiagnostics request can trigger OS command injection in the Autel Maxi Charger Single firmware V1.03.51. The vulnerability, classified as CWE‑78, allows a malicious or compromised OCPP server to supply a diagnostics URL that is executed on the charging station, giving an attacker arbitrary command execution capability and potentially full control of the device.

Affected Systems

Autel Maxi Charger Single devices running firmware version 1.03.51 are impacted. No other product or version information is listed.

Risk and Exploitability

The CVSS v3.1 score of 9.5 indicates critical severity. The EPSS score of 1% indicates a low but non‑zero probability of exploitation in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers can exploit the flaw by acting as a rogue OCPP server or by compromising an existing server, after which they send a malicious GetDiagnostics command over the network. Successful exploitation leads to arbitrary command execution without requiring local user interaction or elevated privileges on the device.

Generated by OpenCVE AI on August 4, 2026 at 05:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Autel that removes the OCPP GetDiagnostics command injection vulnerability.
  • Limit OCPP traffic to trusted, authenticated servers only by implementing network segmentation or firewall rules.
  • Monitor and log GetDiagnostics requests, blocking traffic from untrusted sources when suspicious behavior is detected.

Generated by OpenCVE AI on August 4, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.
Title Command Injection via Malicious OCPP Server
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:37:31.531Z

Reserved: 2026-05-19T13:12:58.413Z

Link: CVE-2026-8986

cve-icon Vulnrichment

Updated: 2026-07-22T19:16:52.945Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:30:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')