CVE-2026-8982

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 21:16

Updated : 2026-07-22 20:17


NVD link : CVE-2026-8982

Mitre link : CVE-2026-8982

CVE.ORG link : CVE-2026-8982


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials