Autel
Autel Maxicharger Single Charger Firmware: vulnerabilidades y CVE
Autel Maxicharger Single Charger Firmware tiene 18 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses8
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8989 | Alta (8.6) | 0.24% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code… |
| CVE-2026-8988 | Alta (8.6) | 0.24% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the… |
| CVE-2026-8987 | Crítica (9.4) | 0.64% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in… |
| CVE-2026-8986 | Crítica (9.5) | 3.3% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that… |
| CVE-2026-8985 | Crítica (10) | 7.1% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to… |
| CVE-2026-8984 | Crítica (10) | 0.91% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download,… |
| CVE-2026-8983 | Crítica (10) | 0.69% | — | 21 jul 2026 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to… |
| CVE-2026-8982 | Crítica (10) | 0.48% | — | 21 jul 2026 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker… |
| CVE-2025-6678 | Alta (7.5) | 0.48% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel… |
| CVE-2025-5830 | Alta (8.8) | 0.39% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected… |
| CVE-2025-5829 | Media (6.8) | 0.34% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected… |
| CVE-2025-5828 | Media (6.8) | 0.34% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel… |
| CVE-2025-5827 | Alta (8.8) | 0.39% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected… |
| CVE-2025-5826 | Media (6.3) | 0.27% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of… |
| CVE-2025-5825 | Alta (7.5) | 0.28% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel… |
| CVE-2025-5824 | Alta (7.5) | 0.17% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel… |
| CVE-2025-5823 | Media (6.5) | 0.55% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations… |
| CVE-2025-5822 | Alta (8.8) | 0.41% | — | 25 jun 2025 | Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Autel
Maxicharger AC Elite Business C50 Firmware · 15Maxicharger AC PRO Firmware · 10Maxicharger AC Ultra Firmware · 10Maxicharger DC Compact Mobile Firmware · 10Maxicharger DC Compact Pedestal Firmware · 10Maxicharger DC Fast Firmware · 10Maxicharger DC Hipower Firmware · 10Maxicharger Dh480 Firmware · 10Maxicharger AC Elite Home · 5