CVE-2026-8988: Access to Bootloader
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Autel Maxi Charger Single: mitigate physical/UART boot tampering by restricting physical access to the device and the UART interface (e.g., disable/exclude UART access or ensure the UART pins/port are inaccessible to attackers).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8988?
CVE-2026-8988 has a high severity rating of 8.6 according to the CVSS scoring system.
How can I mitigate CVE-2026-8988?
To mitigate CVE-2026-8988, ensure physical access to the device is restricted and consider updating to the latest firmware version.
What are the risks associated with CVE-2026-8988?
CVE-2026-8988 poses risks such as unauthorized access to the bootloader, which can lead to modifications of the boot configuration and compromise of the operating system.
Who is affected by CVE-2026-8988?
CVE-2026-8988 affects users of the Autel Maxi Charger Single firmware version up to V1.03.51.
When was CVE-2026-8988 published?
CVE-2026-8988 was published on July 21, 2026.