CVE-2026-8989CWE-1191CWE-1244
CVE-2026-8989
Medium · published July 22, 2026
What it is
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
The record
Technical detail
- CVSS v3.1
- 6.8 · MEDIUM
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00276 · 19.7th percentile
- Weaknesses
- CWE-1191 · On-Chip Debug and Test Interface With Improper Access Control; CWE-1244 · Internal Asset Exposed to Unsafe Debug Access Level or State
- Published
- 2026-07-22T02:19Z
Affected products (2)
| Product | Versions | Fixed in |
|---|
| autel/maxicharger_single_charger_firmware | ≤ 1.03.51 | — |
| autel/maxicharger_single_charger_firmware | ≤ 1.03.51 | — |
References (1)
EPSS history
Timeline
21 JUL 21:24Z
Open Recovery Mode
cvelistv5