peter bassill · operator
$ cve CVE-2026-8985 JSON

CVE-2026-8985

9.8
CRITICAL · CVSS 3.1 · EPSS 7.1% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.09% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-07-21
Last modified2026-08-13

Affected (2)

VendorProduct
autelmaxicharger single charger
autelmaxicharger single charger firmware

References

→ the Explorer  ·  watch your stack  ·  NVD