CVE-2026-8985: Unauthenticated Command Injection
Published Jul 21, 2026
·Updated
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
Affected Software
4 affected components
Autel Maxi Charger Single<=V1.03.51
All of the following
Any of the following
Autel Maxicharger Single Charger Firmware<=1.03.51
Autel Maxicharger Single Charger Firmware<=1.03.51
Autel Maxicharger Single Charger
Event History
Jul 21, 2026
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
DescriptionWeakness
Data Sourced
via NVD·10:19 PM
DescriptionSeverityWeaknessAffected Software
Oct 29, 58588
Event
via FIRST·02:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8985?
CVE-2026-8985 is classified as critical with a severity score of 10.
2
How does CVE-2026-8985 impact the Autel Maxi Charger Single?
CVE-2026-8985 allows unauthenticated attackers to execute arbitrary OS commands via the /test endpoint on TCP port 9002.
3
How do I fix CVE-2026-8985?
To mitigate CVE-2026-8985, it is recommended to update the Autel Maxi Charger Single firmware to a version beyond V1.03.51.
4
What type of vulnerability is CVE-2026-8985 categorized as?
CVE-2026-8985 is categorized as an OS Command Injection vulnerability.
5
Can an attacker exploit CVE-2026-8985 without authentication?
Yes, an unauthenticated attacker can exploit CVE-2026-8985 to execute commands remotely.