Skip to content
COOEY

EXPOSURES › CVE-2026-8986

CVE-2026-8986

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-21 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-8986 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.