Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3wx-h3f8-c23p

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

EPSS

Процентиль: 90%
0.04193
Низкий

10 Critical

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
9 дней назад

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

EPSS

Процентиль: 90%
0.04193
Низкий

10 Critical

CVSS4

Дефекты

CWE-78