CVE-2026-8989

HIGH

Autel MaxiCharger Single - Open Recovery Mode

Title source: rule
STIX 2.1

Description

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

References (1)

Core 1

Scores

CVSS v4 8.6
EPSS 0.0019
EPSS Percentile 8.7%
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-1191 CWE-1244
Status published
Products (1)
Autel/MaxiCharger Single < V1.03.51
Published Jul 21, 2026
Tracked Since Jul 22, 2026