Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfm9-xrwg-mf3r

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.5

Описание

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

EPSS

Процентиль: 66%
0.01215
Низкий

9.5 Critical

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
11 дней назад

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

EPSS

Процентиль: 66%
0.01215
Низкий

9.5 Critical

CVSS4

Дефекты

CWE-78