GHSA-qh3x-7q6p-6x7fCritical

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the...

Published
July 22, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (1)

📋 Description

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

🔗 References (3)