CVE-2026-8986
9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.29% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-07-21 |
| Last modified | 2026-08-13 |
Affected (2)
| Vendor | Product |
|---|---|
| autel | maxicharger single charger |
| autel | maxicharger single charger firmware |
References
→ the Explorer · watch your stack · NVD