Autel Maxicharger Single Charger Firmware — known CVE vulnerabilities
Every CVE whose affected-product data names Autel Maxicharger Single Charger Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (18)
CVE-2026-8986 — CVSS 9.8 (critical): Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A…
CVE-2026-8983 — CVSS 9.8 (critical): Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for…
CVE-2026-8985 — CVSS 9.8 (critical): Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002…
CVE-2026-8984 — CVSS 9.8 (critical): Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port…
CVE-2026-8987 — CVSS 8.8 (high): Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the…
CVE-2025-5822 — CVSS 8.8 (high): Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability…
CVE-2026-8982 — CVSS 8.1 (high): Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password…
CVE-2025-6678 — CVSS 7.5 (high): Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote…
CVE-2025-5824 — CVSS 7.5 (high): Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows…
CVE-2025-5825 — CVSS 7.5 (high): Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent…
CVE-2025-5829 — CVSS 6.8 (medium): Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability…
CVE-2026-8988 — CVSS 6.8 (medium): Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and…
CVE-2026-8989 — CVSS 6.8 (medium): Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware…
CVE-2025-5823 — CVSS 6.5 (medium): Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability…
CVE-2025-5826 — CVSS 6.3 (medium): Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows…