Security Advisory

CVE-2026-8986

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-21 21:14:26
Last updated 2026-07-22 19:37:31
Assigner CyberDanube
CVSS score 9.5
State PUBLISHED

Description

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.