Junglewise Threat Intelligence

CVE-2026-8987: Autel MaxiCharger Single heap overflow in set_ap_param command

CVE-2026-8987 · Severity: info · CVSS 9.4 · Published 2026-07-21

Technologies: Autel MaxiCharger Single. Vendors: Autel.

Executive brief

Autel MaxiCharger Single electric vehicle charging stations are affected by a memory corruption vulnerability. An attacker with valid credentials can send specially crafted commands to the device to cause a system crash or potentially take full control of the charger. This could lead to service disruptions, unauthorized configuration changes, or a complete loss of control over the charging infrastructure.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Autel MaxiCharger Single firmware up to version V1.03.51. The vulnerability is located within the 'set_ap_param' command processing logic of the '/localcfg' HTTP endpoint. An authenticated attacker can exploit this by sending a crafted POST request containing oversized input data, leading to heap memory corruption. Successful exploitation can result in a denial-of-service (DoS) condition via a system crash or potentially arbitrary code execution (RCE) with the privileges of the web service. While authentication is required, other vulnerabilities in the same advisory (such as CVE-2026-8982 or CVE-2026-8983) may allow attackers to obtain the necessary credentials or bypass authentication entirely.

Affected products

  • Autel MaxiCharger Single through V1.03.51

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-09-06: disclosed: CyberDanube research publication date

References

Related threats