CVE-2026-8987 Details
Description
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
A heap-based buffer overflow vulnerability has been identified in the Autel Maxi Charger Single firmware versions through V1.03.51. The issue arises in the set_ap_param command, which is processed by the /localcfg endpoint. An authenticated attacker can exploit this vulnerability by sending oversized input, leading to a denial-of-service condition and potentially allowing arbitrary code execution.
Users are advised to update to the latest available version and/or upgrade hardware. Additionally, restrict network access to/from devices and do not leave devices unattended due to physical attack vectors.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cyberdanube.com/security-research/multiple-vulnerabilities-in-autel-maxi-charger/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| autel maxicharger single charger firmware | <= 1.03.51 |
CPE
Remediation
| |
| autel maxicharger single charger | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 13, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |