CVE-2026-8985
NONE—CVSS v3
—CVSS v2
4.19%
EPSS (exploit probability)
CWE-78CWE
Description
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Affected routers (0)
No routers currently mapped to this CVE in our database.