Skip to main content

Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Severity

CVSS 4.0 · CNA10 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC · CISA-ADP
Exploitationpoc
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
AutelMaxiCharger Single
0 to V1.03.51

References

1 Links

Record Details

Published
2026-07-21
Last updated
2026-07-22
Assigner (CNA)
CyberDanube
Credited to
S. Eisenreich-Dietz (CyberDanube); T. Weber (CyberDanube); D. Blagojevic (CyberDanube); F. Koroknai (CyberDanube)

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.