External risk intelligence

Autel Maxi Charger Authentication Bypass via Hard-coded Token

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-8983

The affected product is an electric vehicle charging station. Such devices are frequently deployed in public-facing locations or networked environments where they are accessible via the internet for management, monitoring, and remote operation, making them a plausible target for internet-based discovery and interaction.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability involves a hard-coded authentication token in Autel Maxi Charger devices, allowing unauthenticated access to sensitive management functions. The issue impacts technology used for electric vehicle charging infrastructure. The primary concern is to confirm if these devices are in use and if they are exposed to potential unauthorized access.

  • Hard-coded token bypasses authentication for chargers.
  • Critical to confirm if charging devices are exposed.
  • Understand risk; confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach and trigger this vulnerability by interacting with the device over the network. No authentication is needed to access specific management functions because a hard-coded token bypasses authorization checks. This allows an attacker to invoke privileged operations, potentially leading to unauthorized control or data access.

  • Network access required.
  • Special token bypasses authorization.
  • Unauthenticated privileged function access.

Live Threat

Current exploitation, exposure, and threat context

The Autel Maxi Charger Single's hard-coded authentication token could allow an unauthorized attacker to access and control management functions. This could occur when the device is accessible over a network, potentially enabling unauthorized operations or configuration changes. No specific PII or sensitive data types are mentioned as being at risk.

  • Management endpoints and functions.
  • Via network access by supplying a special token.
  • Unauthorized control of charging functions.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Autel Maxi Charger Single firmware's hard-coded authentication token presents a critical risk, allowing unauthenticated access to privileged functions. Ownership likely falls to teams managing operational technology (OT) or industrial control systems (ICS), potentially collaborating with network and security teams. The first practical step is to identify all deployed Maxi Charger units, determine their network exposure, and confirm which are actively managed or remotely accessible.

  • Identify affected devices and their exposure.
  • Confirm device ownership and criticality.
  • Plan vendor engagement for firmware updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Autel Maxi Charger Single?

The Autel Maxi Charger Single is an electric vehicle charging station. These devices are used to provide power to electric vehicles and often include network-connected features that allow owners or operators to manage charging sessions, monitor device health, and perform remote configuration tasks.

What does CVE-2026-8983 mean?

This CVE describes a security weakness known as CWE-798, which is the use of a hard-coded authentication token. In this specific case, the charger's firmware includes a secret key embedded directly into the software that is used to verify identities. Because this token is constant, an attacker can use it to pretend they are an authorized user, bypassing the normal security checks that would otherwise prevent unauthorized access to sensitive management functions.

How can an attacker trigger this vulnerability?

An attacker can trigger this flaw by sending a network request to the device that includes the specific hard-coded token. No special user interaction is required, and the attacker does not need to guess a password. Please note that this vulnerability requires network access to the device's management endpoints; it cannot be triggered by physically interacting with the charger's charging cable or the vehicle itself.

Is my Autel Maxi Charger at risk?

According to Halo Surface Signal, these chargers are often deployed in public-facing locations or networked environments to support remote management. If your devices are reachable over the internet, they are at higher risk of being discovered and targeted. You should prioritize assessing any units that are connected to external-facing networks rather than those kept on strictly isolated, internal-only infrastructure.

What should I do if I manage these chargers?

Your first step is to create an inventory of all deployed Autel Maxi Charger units within your environment. Once you have identified the devices, determine which ones have network connectivity that could allow remote access. After cataloging your assets and their network exposure, coordinate with your internal IT or OT teams to plan for vendor-provided firmware updates that replace the hard-coded token.

References