Two undocumented privileged accounts exist in Autel Maxi...
Critical severity
Unreviewed
Published
Jul 21, 2026
to the GitHub Advisory Database
•
Updated Aug 12, 2026
Description
Published by the National Vulnerability Database
Jul 21, 2026
Published to the GitHub Advisory Database
Jul 21, 2026
Last updated
Aug 12, 2026
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.
References