Executive brief
Autel MaxiCharger Single electric vehicle charging stations are affected by a memory corruption vulnerability. An attacker with valid credentials can send specially crafted commands to the device to cause a system crash or potentially take full control of the charger. This could lead to service disruptions, unauthorized configuration changes, or a complete loss of control over the charging infrastructure.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Autel MaxiCharger Single firmware up to version V1.03.51. The vulnerability is located within the 'set_ap_param' command processing logic of the '/localcfg' HTTP endpoint. An authenticated attacker can exploit this by sending a crafted POST request containing oversized input data, leading to heap memory corruption. Successful exploitation can result in a denial-of-service (DoS) condition via a system crash or potentially arbitrary code execution (RCE) with the privileges of the web service. While authentication is required, other vulnerabilities in the same advisory (such as CVE-2026-8982 or CVE-2026-8983) may allow attackers to obtain the necessary credentials or bypass authentication entirely.
Affected products
- Autel MaxiCharger Single through V1.03.51
Timeline
- 2026-07-21: advisory: NVD publication date
- 2026-09-06: disclosed: CyberDanube research publication date