CVE-2026-8986: Command Injection via Malicious OCPP Server
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8986?
CVE-2026-8986 has a critical severity rating of 9.5 according to the CVSS scoring system.
How does CVE-2026-8986 exploit OS command injection?
CVE-2026-8986 exploits OS command injection by allowing a malicious OCPP server to send crafted diagnostics URLs to the Autel Maxi Charger Single.
Who is affected by CVE-2026-8986?
Users of the Autel Maxi Charger Single firmware version V1.03.51 are affected by CVE-2026-8986.
What are the potential consequences of CVE-2026-8986?
The potential consequences of CVE-2026-8986 include arbitrary command execution on the charging station, leading to potential system compromise.
How can I mitigate the risk of CVE-2026-8986?
Mitigating the risk of CVE-2026-8986 involves updating the firmware of the Autel Maxi Charger Single to a patched version that addresses the command injection vulnerability.