« Volver al listado

Autel

Autel Maxicharger Single Charger Firmware: vulnerabilidades y CVE

Autel Maxicharger Single Charger Firmware tiene 18 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE18
Últimos 12 meses8
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-8989Alta (8.6)0.24%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code…
CVE-2026-8988Alta (8.6)0.24%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the…
CVE-2026-8987Crítica (9.4)0.64%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in…
CVE-2026-8986Crítica (9.5)3.3%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that…
CVE-2026-8985Crítica (10)7.1%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to…
CVE-2026-8984Crítica (10)0.91%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download,…
CVE-2026-8983Crítica (10)0.69%—21 jul 2026
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to…
CVE-2026-8982Crítica (10)0.48%—21 jul 2026
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker…
CVE-2025-6678Alta (7.5)0.48%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel…
CVE-2025-5830Alta (8.8)0.39%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected…
CVE-2025-5829Media (6.8)0.34%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected…
CVE-2025-5828Media (6.8)0.34%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel…
CVE-2025-5827Alta (8.8)0.39%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected…
CVE-2025-5826Media (6.3)0.27%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of…
CVE-2025-5825Alta (7.5)0.28%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel…
CVE-2025-5824Alta (7.5)0.17%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel…
CVE-2025-5823Media (6.5)0.55%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-5822Alta (8.8)0.41%—25 jun 2025
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter7
  2. T1190 Exploit Public-Facing Application6
  3. T1210 Exploitation of Remote Services6
  4. T1068 Exploitation for Privilege Escalation2
  5. T1078 Valid Accounts2
  6. T1078.001 Default Accounts2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Autel