Impact
An exposed UART interface on the Autel Maxi Charger Single firmware V1.03.51 permits interruption of the boot sequence and direct access to the U‑Boot bootloader. This flaw allows an attacker with physical access to alter boot settings or modify the file system, giving them the ability to run arbitrary code on the device's operating system. The weakness is classified as CWE‑1191, reflecting a user‑controlled data flow that can compromise system integrity.
Affected Systems
Autel Maxi Charger Single devices running firmware version 1.03.51 are affected. No other products or version ranges the vendor advisory.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability, yet the EPSS score of less than 1% suggests that active exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The attack path requires physical attacker can freely modify the boot configuration or file persistent compromise of the device's operating system. Physical security controls, disabling or locking the UART port, and firmware updates are critical mitigations.
OpenCVE Enrichment