← Back to browse · API

CVE-2026-8982

Severity
CRITICAL
CVSS
10.0
EPSS
0.00384
Risk score
40.13
CISA KEV
No
PoC
No
Published
2026-07-21
Modified
2026-07-22
First seen
2026-08-05
Aliases
EUVD-2026-46430, GHSA-7RV7-46CM-G66M
Products
Autel:MaxiCharger Single 0 ≤V1.03.51, autel:maxicharger_single_charger, autel:maxicharger_single_charger_firmware
Sources
nvd CVE-2026-8982
euvd EUVD-2026-46430

Description

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.

References