CVE-2026-8987
NONE—CVSS v3
—CVSS v2
0.36%
EPSS (exploit probability)
CWE-122CWE
Description
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
Affected routers (0)
No routers currently mapped to this CVE in our database.