CVE-2026-8984

Autel · MaxiCharger Single

A remote code execution vulnerability in the Autel MaxiCharger Single firmware allows unauthenticated attackers to execute commands with root privileges via TCP port 9002.

Executive summary

An unauthenticated remote code execution vulnerability in the Autel MaxiCharger Single firmware allows attackers to gain full root-level control of the device.

Vulnerability

This is an unauthenticated remote code execution vulnerability (CWE-94) triggered by sending a crafted request to the /test endpoint on TCP port 9002, which forces the device to download and execute arbitrary files.

Business impact

A successful exploit provides the attacker with root-level access to the charging station, which could be used to pivot into the local network or cause physical hardware malfunction. Given the CVSS score of 10, this represents the highest level of risk, as the device can be fully compromised without any prior authentication.

Remediation

Immediate Action: Update the Autel MaxiCharger Single firmware to a version beyond V1.03.51 immediately.

Proactive Monitoring: Monitor network traffic for unusual connections or attempts to access TCP port 9002 from unauthorized IP addresses.

Compensating Controls: Isolate the charging station on a dedicated, firewalled VLAN to prevent direct access from the public internet or untrusted segments of the internal network.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is critical and requires immediate firmware remediation. Owners of Autel MaxiCharger Single units should ensure their devices are not exposed to the public internet and apply the latest available firmware update to eliminate the command execution risk.