SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-8985

CRITICAL · CVSS 9.8 EPSS 6.60%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Autel Maxi Charger Single firmware versions prior to V1.03.51 are susceptible to OS command injection via the /test endpoint on TCP port 9002. This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands by manipulating the URL parameters. Organizations utilizing this firmware should prioritize patching to mitigate the risk of unauthorized command execution.

CVE
CVE-2026-8985
Severity
CRITICAL
CVSS
9.8
EPSS
6.60%

Original NVD Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Related CVEs

Other vulnerabilities affecting the same vendor(s)