Vulnerability Details CVE-2026-8985
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.042
EPSS Ranking 90.0%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-8985
-
cpe:2.3:h:autel:maxicharger_single_charger:-
-
cpe:2.3:o:autel:maxicharger_single_charger_firmware:-