SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-8982

HIGH · CVSS 8.1 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Autel Maxi Charger Single firmware versions up to V1.03.51 contain two undocumented privileged accounts that can be exploited due to vendor-defined password derivation mechanisms. This vulnerability allows an attacker with knowledge of the algorithm and necessary inputs to gain unauthorized administrative access to the web management interface, potentially compromising the device's security and functionality. Organizations utilizing this firmware should prioritize addressing this issue to mitigate risks associated with unauthorized access.

CVE
CVE-2026-8982
Severity
HIGH
CVSS
8.1
EPSS
0.38%

Original NVD Description

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.

Related CVEs

Other vulnerabilities affecting the same vendor(s)