
同じ Autel 充電器に、認可検査を迂回するハードコードされた認証トークン。特別な値を送るだけで管理機能を未認証で呼べます。厄介なのは、管理画面のパスワードを強くしても消えないこと。埋め込まれた資格情報はファームウェア更新でしか取り除けません。 https://cve.autoarticles.net/cve/CVE-2026-8983
Post summary
The post highlights a hard‑coded auth token in Autel chargers that bypasses authorization and notes that removing the embedded credentials requires a firmware update, implying a vendor patch is needed.
