VYPR
Vendor

Autel

Products
16
CVEs
29
Across products
134
Status
Private

Products

16

Recent CVEs

29
View all 29 CVEs →
  • CVE-2026-8986CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.02

    Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

  • CVE-2026-8985CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.07

    Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

  • CVE-2026-8984CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root…

  • CVE-2026-8983CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.00

    Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.

  • CVE-2026-8987HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.01

    Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

  • CVE-2025-5830HigJun 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV…

  • CVE-2025-5827HigJun 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV…

  • CVE-2025-5822HigJun 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An…

  • CVE-2024-23957HigSep 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Autel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 charging…

  • CVE-2024-7795HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50…

  • CVE-2026-8982HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to…

  • CVE-2024-23967HigSep 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Autel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50…

  • CVE-2024-23959HigSep 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Autel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50…

  • CVE-2025-6678HigJun 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations.…

  • CVE-2025-5825HigJun 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must…

  • CVE-2025-5824HigJun 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Commercial. An attacker must first obtain…

  • CVE-2026-8989MedJul 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive…

  • CVE-2026-8988MedJul 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating…

  • CVE-2025-5829MedJun 25, 2025
    risk 0.44cvss 6.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected installations of Autel MaxiCharger AC Wallbox Commercial EV…

  • CVE-2025-5828MedJun 25, 2025
    risk 0.44cvss 6.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication…