← Vulnerability feed

Vulnerability record · CVE-2026-8984 · published 21 July 2026

CVE-2026-8984: Autel maxicharger single charger firmware code injection vulnerability

Autel · Maxicharger Single Charger Firmware

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

10.0 CVSS 4.0 Critical EPSS 0.91% · top 41.8% CWE-94 · Code injection
10.0CVSS 4.0 base score
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
13 Aug 2026Last modified by NVD

Description

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8984 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-8985Autel maxicharger single charger firmware os command injection vulnerabilityAutel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthen…EPSS 7.1%10.0CVE-2026-8982Autel maxicharger single charger firmware hard-coded credentials vulnerabilityTwo undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivatio…EPSS 0.48%10.0CVE-2026-8983Autel maxicharger single charger firmware hard-coded credentials vulnerabilityAutel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple manage…EPSS 0.69%9.5CVE-2026-8986Autel maxicharger single charger firmware os command injection vulnerabilityAutel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious o…EPSS 3.3%9.4CVE-2026-8987Autel maxicharger single charger firmware heap-based buffer overflow vulnerabilityAutel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoi…EPSS 0.64%8.8CVE-2025-5827Autel maxicharger ac elite business c50 firmware stack-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all…EPSS 0.39%8.8CVE-2025-5830Autel maxicharger ac elite business c50 firmware heap-based buffer overflow vulnerabilityAutel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows n…EPSS 0.39%8.8CVE-2025-5822Autel maxicharger ac elite business c50 firmware incorrect authorization vulnerabilityAutel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2026-8984), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.