CVE-2026-8982

Autel · MaxiCharger Single

The Autel MaxiCharger Single firmware contains undocumented privileged accounts with deterministic password derivation, allowing attackers to gain unauthorized administrative access.

Executive summary

The presence of hard-coded, undocumented administrative accounts in Autel MaxiCharger Single firmware creates a critical risk of unauthorized remote management access.

Vulnerability

This vulnerability involves the use of hard-coded credentials or mechanisms (CWE-798) that allow unauthorized authentication. An attacker who understands the password derivation algorithm can authenticate as an administrator without valid credentials.

Business impact

An attacker gaining administrative access can modify device configurations, intercept data, or potentially disable safety mechanisms of the charging hardware. This unauthorized access constitutes a total loss of confidentiality, integrity, and availability, warranting a critical CVSS score of 10.0.

Remediation

Immediate Action: Update the device firmware to the latest version provided by the manufacturer to remove the undocumented accounts.

Proactive Monitoring: Review device authentication logs for logins occurring from unknown or unauthorized sources, specifically targeting the web management interface.

Compensating Controls: Restrict access to the device management interface to trusted administrative subnets only, effectively limiting the attack surface for remote management attempts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The existence of backdoored or undocumented accounts is a severe security failure. Organizations should verify their firmware versions and apply the necessary updates immediately to ensure that only authorized, documented accounts have access to administrative functions.