CVE-2026-8984EPSS p58.5%
CVE-2026-8984CVE-2026-8984
autel / maxicharger_single_charger_firmware
Description
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.91% probability of exploitation · percentile 58.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-13 |