← Back to browse · API

CVE-2026-8983

Severity
CRITICAL
CVSS
10.0
EPSS
0.00429
Risk score
40.15
CISA KEV
No
PoC
No
Published
2026-07-21
Modified
2026-07-22
First seen
2026-08-05
Aliases
EUVD-2026-46432, GHSA-HMFC-F829-2XF3
Products
Autel:MaxiCharger Single 0 ≤V1.03.51, autel:maxicharger_single_charger, autel:maxicharger_single_charger_firmware
Sources
nvd CVE-2026-8983
euvd EUVD-2026-46432

Description

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.

References