CVE-2026-8984: Unauthenticated RCE
Published Jul 21, 2026
·Updated
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
Affected Software
4 affected components
Autel Maxi Charger Single<=V1.03.51
All of the following
Any of the following
Autel Maxicharger Single Charger Firmware<=1.03.51
Autel Maxicharger Single Charger Firmware<=1.03.51
Autel Maxicharger Single Charger
Event History
Jul 21, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Data Sourced
via NVD·10:19 PM
DescriptionSeverityWeaknessAffected Software
Oct 29, 58588
Event
via FIRST·06:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8984?
CVE-2026-8984 has a critical severity rating of 10.
2
What type of vulnerability is CVE-2026-8984?
CVE-2026-8984 is an unauthenticated remote code execution vulnerability.
3
How does CVE-2026-8984 exploit work?
CVE-2026-8984 allows an attacker to send a crafted request to the /test endpoint, leading to remote code execution.
4
What software is affected by CVE-2026-8984?
CVE-2026-8984 affects the Autel Maxi Charger Single firmware versions prior to V1.03.51.
5
How can I mitigate the risk of CVE-2026-8984?
To mitigate CVE-2026-8984, you should immediately update the Autel Maxi Charger Single firmware to the latest version.