Junglewise Threat Intelligence

CVE-2026-8982: Autel MaxiCharger Single undocumented privileged accounts

CVE-2026-8982 · Severity: info · CVSS 10 · Published 2026-07-21

Technologies: Autel MaxiCharger Single. Vendors: Autel.

Executive brief

The Autel MaxiCharger Single, an electric vehicle charging station, contains two undocumented administrative accounts. These accounts allow anyone with knowledge of the manufacturer's password generation method to log into the charger's web management interface with full administrative privileges. An attacker could use this access to change device configurations, disrupt charging services, or gain a foothold in the local network.

Technical details

The Autel MaxiCharger Single firmware (up to V1.03.51) contains two undocumented accounts: 'super_admin' and 'config_admin'. These accounts utilize a vendor-defined password derivation mechanism (CWE-798) based on device-specific values such as a 6-digit PIN, MAC address, and serial number. The 'super_admin' account is particularly vulnerable as its password can be derived from a 6-digit PIN that is easily guessable or brute-forced. An unauthenticated attacker with network access to the web management interface can use these derived credentials to gain administrative control over the device. This vulnerability was disclosed alongside several other critical flaws in the same product line, including unauthenticated RCE and command injection.

Affected products

  • Autel MaxiCharger Single through V1.03.51

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-09-06: disclosed: CyberDanube security research published

References

Related threats