Authentication Bypass Vulnerability in Autel Maxi Charger by Autel
CVE-2026-8983
10CRITICAL
What is CVE-2026-8983?
The Autel Maxi Charger Single firmware prior to version 1.03.51 is susceptible to an authentication bypass vulnerability due to a hard-coded authentication token. This flaw allows attackers to bypass authorization checks for critical management endpoints, enabling them to execute privileged functionalities without proper authentication. Exploiting this vulnerability could result in unauthorized access and manipulation of charger settings, posing significant security risks.
Affected Version(s)
MaxiCharger Single 0
References
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
S. Eisenreich-Dietz (CyberDanube)
T. Weber (CyberDanube)
D. Blagojevic (CyberDanube)
F. Koroknai (CyberDanube)
