Junglewise Threat Intelligence

CVE-2026-8984: Autel MaxiCharger Single unauthenticated RCE in port 9002 service

CVE-2026-8984 · Severity: info · CVSS 10 · Published 2026-07-21

Technologies: Autel MaxiCharger Single. Vendors: Autel.

Executive brief

Autel MaxiCharger Single electric vehicle charging stations are vulnerable to a critical security flaw that allows unauthorized individuals to take complete control of the device over a network. By sending a specially crafted request to a specific service on the charger, an attacker can force the device to download and run malicious software. This could lead to a total service outage, theft of data, or the use of the charging infrastructure for further attacks on the corporate network.

Technical details

A remote code execution vulnerability exists in the Autel MaxiCharger Single firmware (up to V1.03.51) due to improper handling of requests in a service listening on TCP port 9002. An unauthenticated attacker can send a HTTP POST request to the '/test' endpoint containing JSON data with a URL pointing to a malicious archive. The device's service will download the archive, extract its contents, and execute a script named 'install.sh' with root privileges. This allows for full system compromise without requiring valid credentials or user interaction. The vulnerability is tracked as CWE-94 (Improper Control of Generation of Code).

Affected products

  • Autel MaxiCharger Single through V1.03.51

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-09-06: disclosed: CyberDanube research publication date

References

Related threats