Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qpp-vgrg-5mhj

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8

Описание

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

EPSS

Процентиль: 54%
0.00766
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

EPSS

Процентиль: 54%
0.00766
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94