CVE-2026-8985

NONE
CVSS v3
CVSS v2
4.19% EPSS (exploit probability)
CWE-78CWE

Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references