CVE-2026-8987

CVE-2026-8987CVE-2026-8987

Description

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

Scoring

Last modified2026-07-21
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.