SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-8989

MEDIUM · CVSS 6.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Autel Maxi Charger Single firmware versions prior to V1.03.51 are vulnerable due to exposed hardware recovery pins that allow unrestricted access to the NXP i.MX6 recovery mode. An attacker with physical access can exploit this vulnerability to boot malicious code, potentially modifying or extracting sensitive firmware and data. Organizations using this device should prioritize addressing this vulnerability to mitigate risks associated with unauthorized physical access.

CVE
CVE-2026-8989
Severity
MEDIUM
CVSS
6.8
EPSS
0.28%

Original NVD Description

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

Related CVEs

Other vulnerabilities affecting the same vendor(s)