CVE-2026-8983: Backdoor Authentication Token
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8983?
CVE-2026-8983 has a severity rating of critical with a CVSS score of 10.
How do I fix CVE-2026-8983?
To fix CVE-2026-8983, update the Autel Maxi Charger Single firmware to the latest version that addresses the hard-coded authentication token.
What type of vulnerability is CVE-2026-8983?
CVE-2026-8983 is classified as a backdoor vulnerability due to the presence of a hard-coded authentication token.
What impact does CVE-2026-8983 have on security?
CVE-2026-8983 allows attackers to bypass authorization checks, enabling them to invoke privileged functions without authentication.
Which software is affected by CVE-2026-8983?
CVE-2026-8983 affects the Autel Maxi Charger Single firmware version V1.03.51.