CVE-2026-8988CWE-1191

CVE-2026-8988

Medium · published July 22, 2026

CVSS v3.1
6.8
EPSS
0%
Percentile
12.8
In the wild
Unconfirmed
What it is

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00223 · 12.8th percentile
Weakness
CWE-1191 · On-Chip Debug and Test Interface With Improper Access Control
Published
2026-07-22T02:19Z
Affected products (2)
ProductVersionsFixed in
autel/maxicharger_single_charger_firmware≤ 1.03.51
autel/maxicharger_single_charger_firmware≤ 1.03.51
References (1)
EPSS history
Timeline
  • 21 JUL 21:21Z
    Access to Bootloader
    cvelistv5