Vulnerability Details CVE-2026-8985
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.066
EPSS Ranking 93.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-8985
-
cpe:2.3:h:autel:maxicharger_single_charger:-
-
cpe:2.3:o:autel:maxicharger_single_charger_firmware:-