← Back to browse · API

CVE-2026-8985

Severity
CRITICAL
CVSS
10.0
EPSS
0.04193
Risk score
41.47
CISA KEV
No
PoC
No
Published
2026-07-21
Modified
2026-07-22
First seen
2026-08-05
Aliases
EUVD-2026-46639, GHSA-G3WX-H3F8-C23P
Products
Autel:MaxiCharger Single 0 ≤V1.03.51
Sources
nvd CVE-2026-8985
euvd EUVD-2026-46639

Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

References