CVE-2026-8983
CWE-798Published: July 21, 2026· Updated: Jul 21, 2026
Official Description
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.
Risk Analysis
Autel Maxi Charger Single firmware contains a hard-coded authentication token, allowing unauthenticated attackers to bypass authorization and access privileged functions. With a CVSS score of 10.0, this is a critical security failure.
No public exploit is known, and it is not in the CISA KEV. The vulnerability is remotely exploitable with low complexity.
Update the device firmware to a version that removes the hard-coded authentication token.
Technical Analysis
CVE-2026-8983 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
All References (1)
Quick Facts
Related CVEs (CWE-798)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-8983 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts