CVE-2026-8982: Hard-coded / Backdoor Accounts
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8982?
The severity of CVE-2026-8982 is classified as critical with a CVSS score of 10.
What are the potential risks of CVE-2026-8982?
CVE-2026-8982 poses risks of unauthorized access through hard-coded privileged accounts, which can be exploited by attackers.
How do I fix CVE-2026-8982?
To mitigate CVE-2026-8982, update the Autel Maxi Charger Single firmware to a version that removes or secures the hard-coded accounts.
Who is affected by CVE-2026-8982?
CVE-2026-8982 affects users of Autel Maxi Charger Single firmware versions up to and including V1.03.51.
What can an attacker do with CVE-2026-8982?
An attacker exploiting CVE-2026-8982 can gain unauthorized access to the web management interface of the device.