Description
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who can physically reach the device to use exposed hardware recovery pins to initiate the NXP i.MX6 recovery mode without any authentication. Once in recovery mode, the attacker can run code stored in memory, tamper with firmware, or read proprietary firmware and other sensitive information. The weakness is an information disclosure and arbitrary code execution flaw (CWE‑1191, CWE‑1244).

Affected Systems

Autel Maxi Charger Single devices running firmware versions up to and including V1.03.51 are affected.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity. The EPSS score of less than 1% shows that active exploitation is currently unlikely, and the issue is not listed in CISA KE. Malicious insiders or someone who obtains the device can exploit the flaw. Attackers would need to observe the recovery pins, power the device such that the pins trigger recovery mode, load custom code into memory, and then execute it. Once executed, the attacker can rewrite or exfiltrate firmware and sensitive data, presenting a serious risk to confidentiality and integrity for physical asset owners.

Generated by OpenCVE AI on July 30, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Autel Maxi Charger firmware that disables or protects the hardware recovery pins.
  • Secure the device physically by locking or tamper‑evident enclosures to prevent unauthorized access to the recovery circuitry.
  • Audit for unauthorized activation of recovery mode and block any attempts to load unauthorized firmware via device management tools.

Generated by OpenCVE AI on July 30, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Autel
Autel maxicharger Single Charger
Vendors & Products Autel
Autel maxicharger Single Charger

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
Title Open Recovery Mode
Weaknesses CWE-1191
CWE-1244
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Autel Maxicharger Single Charger
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-22T19:37:14.371Z

Reserved: 2026-05-19T13:13:01.023Z

Link: CVE-2026-8989

cve-icon Vulnrichment

Updated: 2026-07-22T19:18:11.721Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:15:04Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control

  • CWE-1244

    Internal Asset Exposed to Unsafe Debug Access Level or State