peter bassill · operator
$ cve CVE-2026-8986 JSON

CVE-2026-8986

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.29% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-07-21
Last modified2026-08-13

Affected (2)

VendorProduct
autelmaxicharger single charger
autelmaxicharger single charger firmware

References

→ the Explorer  ·  watch your stack  ·  NVD