CVE-2026-8982
CWE-798Published: July 21, 2026· Updated: Jul 21, 2026
Official Description
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.
Risk Analysis
The Autel Maxi Charger Single firmware contains undocumented privileged accounts with predictable passwords, allowing unauthorized administrative access. This critical vulnerability has a CVSS score of 10.0.
No public exploit is known, and it is not in the CISA KEV. The vulnerability is remotely exploitable.
Update the device firmware to a version that removes these undocumented accounts.
Technical Analysis
CVE-2026-8982 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
All References (1)
Quick Facts
Related CVEs (CWE-798)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-8982 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts