Description
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
Published: 2026-07-21
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a heap‑based buffer overflow in the set_ap_param command that the /localcfg endpoint processes. Because of the overflow, an attacker can supply an oversized payload, causing the device to crash or, if memory corruption is exploitable, arbitrary code may be executed. The primary impact is a denial of service with the possibility of arbitrary code execution.

Affected Systems

The vulnerability affects the Autel Maxi Charger Single firmware version V1.03.51. Only this specific device and firmware release are noted as susceptible.

Risk and Exploitability

The CVSS score of 9.4 marks it as a high‑severity issue, yet the EPSS score of less than 1% suggests that, as of now, exploitation attempts are rare. Based on the description, it is inferred that an authenticated attacker can potentially execute arbitrary code if the memory corruption can be exploited. The attacker must be authenticated to construct the overflow; this suggests the attack vector may involve authenticated access, which could be local or remote. While the risk is high, current likelihood is low and the vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on July 30, 2026 at 16:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to a firmware version that contains the heap‑overflow fix, such as V1.03.52 or later.
  • Limit network access to the /localcfg endpoint by applying firewall rules or network segmentation so that only trusted, authenticated users can reach it.
  • Use strong, unique credentials for device access and regularly audit access logs for unusual activity.

Generated by OpenCVE AI on July 30, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
Title Authenticated Heap Overflow
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:37:25.824Z

Reserved: 2026-05-19T13:12:59.230Z

Link: CVE-2026-8987

cve-icon Vulnrichment

Updated: 2026-07-22T19:17:22.604Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:30:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow