PT-2026-62420 · Autel · Maxicharger Single

·

CVE-2026-8989

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

8.6

High

VectorAV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

Exploit

Fix

Unsafe Debug Access Level

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8989

Affected Products

Maxicharger Single