Junglewise Threat Intelligence

CVE-2026-8988: Autel MaxiCharger Single bootloader access via UART interface

CVE-2026-8988 · Severity: info · CVSS 8.6 · Published 2026-07-21

Technologies: Autel MaxiCharger Single. Vendors: Autel.

Executive brief

The Autel MaxiCharger Single, an electric vehicle charging station, contains a vulnerability where internal hardware components are left accessible. An attacker with physical access to the device's internal circuit board can interrupt the startup process to gain full control over the operating system. This could allow an unauthorized person to modify the charger's software, disable the device, or compromise the integrity of the charging infrastructure.

Technical details

The Autel MaxiCharger Single firmware (up to V1.03.51) fails to secure the hardware debugging interface. A UART console is exposed on the Printed Circuit Board (PCB), which allows an attacker with physical access to interact with the device during its boot sequence. By sending a break signal or specific key sequence, an attacker can interrupt the normal boot process to enter the U-Boot bootloader environment. From this environment, the attacker can modify boot arguments, manipulate the Linux filesystem, and ultimately obtain root-level access to the underlying operating system.

Affected products

  • Autel MaxiCharger Single through V1.03.51

Timeline

  • 2026-07-21: disclosed: CVE published by CyberDanube
  • 2026-07-21: advisory

References

Related threats