CVE-2026-8989CWE-1191CWE-1244

CVE-2026-8989

Medium · published July 22, 2026

CVSS v3.1
6.8
EPSS
0%
Percentile
19.7
In the wild
Unconfirmed
What it is

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00276 · 19.7th percentile
Weaknesses
CWE-1191 · On-Chip Debug and Test Interface With Improper Access Control; CWE-1244 · Internal Asset Exposed to Unsafe Debug Access Level or State
Published
2026-07-22T02:19Z
Affected products (2)
ProductVersionsFixed in
autel/maxicharger_single_charger_firmware≤ 1.03.51
autel/maxicharger_single_charger_firmware≤ 1.03.51
References (1)
EPSS history
Timeline
  • 21 JUL 21:24Z
    Open Recovery Mode
    cvelistv5