SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-8986

CRITICAL · CVSS 9.8 EPSS 2.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Autel Maxi Charger Single firmware versions up to V1.03.51 are susceptible to OS command injection due to improper handling of OCPP GetDiagnostics requests. This vulnerability allows a malicious OCPP server to execute arbitrary commands on the charging station by supplying a specially crafted diagnostics URL. Organizations utilizing this firmware should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-8986
Severity
CRITICAL
CVSS
9.8
EPSS
2.29%

Original NVD Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

Related CVEs

Other vulnerabilities affecting the same vendor(s)