Back to overview

CVE-2026-8989

HIGH Exploitation: PoC
8.6
CVSS 4.0
Description
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

Metadata

CVE ID
CVE-2026-8989
State
PUBLISHED
Assigner
CyberDanube
Reserved
2026-05-19 13:13 UTC
Published
2026-07-21 21:24 UTC
Last updated
2026-07-22 19:37 UTC
Primary CWE
CWE-1191
CWE-1191 On-Chip debug and test interface with improper acce…
Vendor / Product
Autel / MaxiCharger Single
Sources
cve.org  ·  NVD

Severity & Metrics

8.6 HIGH CVSS 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Autel MaxiCharger Single 0 ≤ V1.03.51
Weakness (CWE)
CWESourceDescription
CWE-1191 cna CWE-1191 On-Chip debug and test interface with improper access control
CWE-1244 cna CWE-1244 Internal asset exposed to unsafe debug access level or state
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.6 HIGH 4.0 cna CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview