CVE-2026-8988: Access to Bootloader
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Autel Maxi Charger Single: mitigate physical/UART boot tampering by restricting physical access to the device and the UART interface (e.g., disable/exclude UART access or ensure the UART pins/port are inaccessible to attackers).