Vulnerability Details CVE-2026-8982
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 31.6%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-8982
-
cpe:2.3:h:autel:maxicharger_single_charger:-
-
cpe:2.3:o:autel:maxicharger_single_charger_firmware:-