Vulnerability Details CVE-2026-8987
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-8987
-
cpe:2.3:h:autel:maxicharger_single_charger:-
-
cpe:2.3:o:autel:maxicharger_single_charger_firmware:-