SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-8987

HIGH · CVSS 8.8 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Autel Maxi Charger Single firmware versions up to V1.03.51 are vulnerable to a heap-based buffer overflow in the set_ap_param command at the /localcfg endpoint. An authenticated attacker can exploit this vulnerability by sending oversized input, leading to denial of service and the potential for arbitrary code execution. Organizations using this firmware should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-8987
Severity
HIGH
CVSS
8.8
EPSS
0.51%

Original NVD Description

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

Related CVEs

Other vulnerabilities affecting the same vendor(s)