Horizon Alert
Summary of the vulnerability and why it matters
This CVE involves a critical vulnerability in Autel Maxi Charger Single firmware that could allow unauthenticated remote code execution through a service on TCP port 9002, enabling an attacker to gain root privileges by manipulating a request to the `/test` endpoint.
- Allows remote code execution.
- Critical flaw for network-connected chargers.
- Confirm exposure and relevant device types.
Attack Path
How an attacker could exploit the issue
An attacker can reach the vulnerable service on TCP port 9002 from the internet without needing any credentials. By sending a specially crafted request to the `/test` endpoint, an attacker can cause the device to download and execute arbitrary code with the highest level of system privileges.
- Unauthenticated network access required.
- Crafted request to `/test` endpoint.
- Root-level code execution possible.
Live Threat
Current exploitation, exposure, and threat context
Autel Maxi Charger Single devices, when accessible over a network, could be at risk of unauthorized code execution with root privileges. This could occur through a specially crafted request to the /test endpoint on TCP port 9002, enabling an attacker to download and execute arbitrary files.
- Device firmware and root access.
- Via unauthenticated network request.
- Attacker gains full device control.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Autel Maxi Charger Single firmware presents a critical vulnerability exploitable via TCP port 9002, allowing unauthenticated remote code execution. This impacts device owners, IT infrastructure, and security teams responsible for network-attached operational technology. The immediate first step is to inventory all Autel Maxi Charger Single devices, confirm network exposure and business criticality, identify the accountable owner, and then develop a targeted remediation plan.
- Device owners and infrastructure teams must act.
- Verify network exposure and device criticality.
- Coordinate vendor support for remediation.