CVE-2026-8988: Autel Maxicharger Single Charger Firmware

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.

Affected products

  • Autel Maxicharger Single Charger Firmware: up to and including 1.03.51

Published 2026-07-21. Last modified 2026-08-13.