External risk intelligence

Autel Maxi Charger Undocumented Privileged Accounts Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-8982

The vulnerability affects the web management interface of an EV charging station. Such devices are frequently deployed in public or semi-public locations and rely on network-accessible interfaces for administration and connectivity, making them commonly reachable from the internet or exposed network segments in standard operational deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An undocumented vulnerability exists in Autel Maxi Charger Single firmware, allowing unauthenticated attackers to gain administrative control. This occurs due to two hidden administrative accounts that use a predictable password generation method.

  • Hidden accounts allow unauthorized admin access.
  • Critical for securing EV charging infrastructure.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could gain administrative access to the Autel Maxi Charger's web management interface by exploiting two undocumented privileged accounts. This is possible if the attacker knows the specific algorithm and device-dependent inputs used to derive the passwords for these accounts. Successful authentication would grant them full control over the charging station.

  • No specific access required.
  • Authenticate to web management interface.
  • Full administrative control.

Live Threat

Current exploitation, exposure, and threat context

An attacker could gain administrative access to the web management interface by leveraging undocumented privileged accounts in the Autel Maxi Charger Single firmware. This is possible when the attacker possesses knowledge of the proprietary password derivation algorithm and the necessary device-specific inputs, allowing them to bypass standard authentication.

  • Administrative access to the web interface.
  • Authentication bypass using proprietary algorithms.
  • Unauthorized control of charging station functions.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Autel Maxi Charger Single firmware contains undocumented privileged accounts that could allow unauthorized administrative access. Ownership likely falls to the device owner or the team managing the charging infrastructure, possibly with vendor support. The first practical step is to identify all deployed charging stations, assess their network exposure and business criticality, and then engage the accountable owner for a coordinated remediation plan.

  • Device owners or infrastructure teams should own the issue.
  • Verify network exposure and business criticality first.
  • Plan vendor-coordinated firmware updates or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Autel Maxi Charger?

The Autel Maxi Charger is an electric vehicle (EV) charging station that includes a web-based management interface. This interface is used by operators to configure device settings, manage connectivity, and monitor charging performance. Because these stations are designed to support modern charging infrastructure, they often require network access to function, which allows administrators to interact with the device remotely via the management console.

What does CWE-798 mean for CVE-2026-8982?

CWE-798 refers to the use of hard-coded credentials. In the case of this CVE, the vulnerability stems from two undocumented privileged accounts hidden within the firmware. Rather than using standard authentication, these accounts rely on a predictable password generation method. If an attacker discovers the algorithm and the required device-specific inputs, they can effectively bypass the normal login process to gain full administrative control over the charging station.

How can an attacker trigger this vulnerability?

An attacker triggers this by authenticating to the device's web management interface using the undocumented accounts. This requires knowledge of the underlying password derivation algorithm and specific inputs unique to the target device. Simply reaching the web interface is not enough; the attacker must be able to calculate the correct password based on the device's specific configuration. Passive observation of the network does not trigger this vulnerability.

Is my Autel Maxi Charger at risk?

Halo Surface Signal indicates that this vulnerability is likely relevant because these charging stations are often deployed in public or semi-public areas with network-accessible interfaces. If your specific devices are reachable from the internet or exposed network segments, they are at higher risk. You should review your network topology to determine if the management interface is accessible beyond a local, protected management network.

What are the first steps to address this issue?

Begin by creating an inventory of all Autel Maxi Charger units in your environment to identify which systems are running the affected firmware. Once identified, evaluate the network accessibility of each device's management interface. Contact your vendor or infrastructure lead to discuss the timeline for firmware updates or other necessary mitigations to secure the administrative login process and restrict unauthorized access.

References