Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3wx-h3f8-c23p

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8

Описание

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

EPSS

Процентиль: 93%
0.06596
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

EPSS

Процентиль: 93%
0.06596
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78