CVE-2026-8987
Severity CVSS v4.0:
CRITICAL
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
21/07/2026
Last modified:
13/08/2026
Description
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:american_standard | 1.03.51 (including) | |
| cpe:2.3:o:autel:maxicharger_single_charger_firmware:*:*:*:*:*:*:*:european_standard | 1.03.51 (including) | |
| cpe:2.3:h:autel:maxicharger_single_charger:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



