GHSA-7rv7-46cm-g66mCritical
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51...
🔗 CVE IDs covered (1)
📋 Description
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges.