Description
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exposed UART interface on the Autel Maxi Charger Single firmware V1.03.51 permits interruption of the boot sequence and direct access to the U‑Boot bootloader. This flaw allows an attacker with physical access to alter boot settings or modify the file system, giving them the ability to run arbitrary code on the device's operating system. The weakness is classified as CWE‑1191, reflecting a user‑controlled data flow that can compromise system integrity.

Affected Systems

Autel Maxi Charger Single devices running firmware version 1.03.51 are affected. No other products or version ranges the vendor advisory.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity vulnerability, yet the EPSS score of less than 1% suggests that active exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The attack path requires physical attacker can freely modify the boot configuration or file persistent compromise of the device's operating system. Physical security controls, disabling or locking the UART port, and firmware updates are critical mitigations.

Generated by OpenCVE AI on July 30, 2026 at 16:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest firmware patch that removes or protects the UART interface, ensuring the update includes the fix for the bootloader access flaw.
  • Disable the UART port either by leveraging a can connect.
  • Enforce strict physical security measures around the device to prevent unauthorized tampering with the boot process and to protect against physical access attacks.

Generated by OpenCVE AI on July 30, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
Title Access to Bootloader
Weaknesses CWE-1191
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:37:20.155Z

Reserved: 2026-05-19T13:13:00.389Z

Link: CVE-2026-8988

cve-icon Vulnrichment

Updated: 2026-07-22T19:17:44.794Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:15:04Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control