Junglewise Threat Intelligence

CVE-2026-8985: Autel MaxiCharger Single OS command injection in /test endpoint

CVE-2026-8985 · Severity: info · CVSS 10 · Published 2026-07-21

Technologies: Autel MaxiCharger Single. Vendors: Autel.

Executive brief

Autel MaxiCharger electric vehicle charging stations are vulnerable to a critical security flaw that allows unauthorized individuals to take complete control of the device over the network. By sending a specially crafted request to the charger's management service, an attacker can execute administrative commands without needing a password. This could lead to service disruption, unauthorized configuration changes, or the use of the charger as a foothold to attack other systems on the same network.

Technical details

The Autel MaxiCharger Single firmware (up to V1.03.51) contains an OS command injection vulnerability within the service listening on TCP port 9002. The vulnerability exists in the '/test' endpoint, which processes JSON data via HTTP POST requests. Specifically, the 'url' parameter within the JSON payload is not properly sanitized before being passed to a system execution function. An unauthenticated attacker can exploit this by injecting shell metacharacters into the 'url' value to execute arbitrary operating system commands with root privileges. This allows for full system compromise, including persistent access and data exfiltration.

Affected products

  • Autel MaxiCharger Single through V1.03.51

Timeline

  • 2026-07-21: disclosed: CVE published to NVD
  • 2026-09-06: advisory: Detailed research published by CyberDanube

References

Related threats