SecAlerts
tesla logo

tesla

Security Risk Profile

69
/100
high

Security Risk Score

Comprehensive risk assessment based on 65 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 13, 2017 to present

65
Total CVEs
37
Critical+High
7
Exploited
37
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
37
Critical/High
Risk Level
69/100
high
⚠️ 7 Active Exploits 11 Zero-Days🆕 6Fresh (<7d)📈 6 in Last 30 Days

Severity Distribution

Critical
3
High
34
Medium
13
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
Integer Overflow
3
2
Input Validation
2
3
Command Injection
2
4
Buffer Overflow
2
5
OS Command Injection
1

Most Affected Products

1. Tesla Model 326
2. Tesla Model S20
3. Tesla Model 3 Firmware14
4. ChargePoint Home Flex8
5. Autel MaxiCharger8

Recent Vulnerabilities

See more →
https://www.theregister.com/2026/01/25/pwn2own_automotive_2026_identifies_76_0days/
unknown

Pwn2Own Automotive 2026 uncovers 76 zero-days, pays out more than $1M

1/25/2026⚡ Zero-Day🔧 No Patch
https://www.bleepingcomputer.com/news/security/hackers-get-1-047-000-for-76-zero-days-at-pwn2own-automotive-2026/
unknown

Hackers get $1,047,000 for 76 zero-days at Pwn2Own Automotive 2026

1/23/2026⚠ Exploited⚡ Zero-Day🔧 No Patch
https://www.bleepingcomputer.com/news/security/hackers-exploit-29-zero-day-vulnerabilities-on-second-day-of-pwn2own-automotive/
unknown

Hackers exploit 29 zero-days on second day of Pwn2Own Automotive

1/22/2026⚠ Exploited⚡ Zero-Day🔧 No Patch
https://www.bleepingcomputer.com/news/security/tesla-hacked-37-zero-days-demoed-at-pwn2own-automotive-2026/
unknown

Tesla hacked, 37 zero-days demoed at Pwn2Own Automotive 2026

1/21/2026⚠ Exploited⚡ Zero-Day🔧 No Patch
CVE-2025-34251
CVSS 8.6high

Tesla Telematics Control Unit (TCU) < v2025.14 Authentication Bypass

10/6/2025🔧 No Patch
CVE-2025-6785
CVSS 4.7medium

Tesla Model 3 Physical CAN Bus Injection

9/4/2025🔧 No Patch
CVE-2025-8320
CVSS 8.8EPSS 0%high

(Pwn2Own) Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability

7/30/2025🔧 No Patch
CVE-2025-8321
CVSS 6.8EPSS 0%medium

(Pwn2Own) Tesla Wall Connector Firmware Downgrade Vulnerability

7/30/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/hackers-earn-1-078-750-for-28-zero-days-at-pwn2own-berlin/
unknown

Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin

5/19/2025⚠ Exploited⚡ Zero-Day🔧 No Patch
CVE-2025-2082
CVSS 7.5high

(Pwn2Own) Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability

4/30/2025🔧 No Patch

Monitor tesla in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

tesla Security Vulnerabilities & Risk Score | 65 CVEs | SecAlerts - SecAlerts