Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-8987: Autel Maxi Charger Single Firmware Heap Overflow Risk

CVE-2026-8987 CVE-2026-8987
Summary

The Autel Maxi Charger Single firmware has a vulnerability that allows an authorized attacker to crash the system or execute unauthorized code, potentially leading to data loss or system compromise. This affects the /localcfg endpoint when the set_ap_param command is used. To mitigate this risk, update the firmware to a version higher than V1.03.51.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
autel maxicharger single <= V1.03.51
Original title
Authenticated Heap Overflow
Original description
Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.
Vulnerability type
CWE-122 Heap-based Buffer Overflow
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026