CVE-2026-8985
Unauthenticated Command Injection
10.0
CRITICAL
CVSS 4.0
EPSS 7.1% · 94th pctCWE-78
2026-07-21•Updated 2026-07-22
Description
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Severity
CVSS 4.0 · CNA10 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HSSVC · CISA-ADP
Exploitationpoc
Automatableyes
Technical impacttotal
Affected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Autel | MaxiCharger Single | 0 to V1.03.51 |
References
1 LinksRecord Details
Published
2026-07-21
Last updated
2026-07-22
Assigner (CNA)
CyberDanube
Credited to
S. Eisenreich-Dietz (CyberDanube); T. Weber (CyberDanube); D. Blagojevic (CyberDanube); F. Koroknai (CyberDanube)
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CWE-78 · OS Command Injection
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.