CVE-2026-8989
8.6
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Autel | MaxiCharger Single | 0 <= V1.03.51 | affected |
Weaknesses
- CWE-1191: CWE-1191 On-Chip debug and test interface with improper access control
- CWE-1244: CWE-1244 Internal asset exposed to unsafe debug access level or state
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.