VYPR
Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 22, 2026

Authenticated Heap Overflow

CVE-2026-8987

Description

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.