Junglewise Threat Intelligence

CVE-2026-8989: Autel MaxiCharger Single unrestricted recovery mode access via hardware pins

CVE-2026-8989 · Severity: info · CVSS 8.6 · Published 2026-07-21

Technologies: Autel MaxiCharger Single. Vendors: Autel.

Executive brief

The Autel MaxiCharger Single, an electric vehicle charging station, contains a hardware vulnerability that allows unauthorized access to its internal recovery mode. By physically accessing the device and interacting with specific internal pins, an attacker can bypass security controls to extract sensitive data or install malicious software. This could lead to a complete compromise of the charging station's operations and the theft of proprietary firmware or customer information.

Technical details

The Autel MaxiCharger Single utilizes an NXP i.MX6 processor which, in affected firmware versions up to V1.03.51, permits unrestricted access to the chip's Serial Download Mode (recovery mode). An attacker with physical access to the device's internal PCB can force the processor into this mode by short-circuiting two specific hardware recovery pins. Once in recovery mode, the attacker can boot arbitrary, attacker-controlled code directly into RAM. This bypasses standard boot protections, allowing for the modification or extraction of the device's filesystem, firmware, and other sensitive internal data.

Affected products

  • Autel MaxiCharger Single through V1.03.51

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-09-06: disclosed: CyberDanube research publication date

References

Related threats