Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmfc-f829-2xf3

Опубликовано: 21 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8

Описание

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.

EPSS

Процентиль: 36%
0.00429
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication.

EPSS

Процентиль: 36%
0.00429
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-798