CVE-2025-32063: Enabling SSH server on Infotainment ECU
There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server.
First identified on Nissan Leaf ZE1 manufactured in 2020.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32063?
CVE-2025-32063 is considered a medium severity vulnerability due to potential unauthorized access capabilities.
How do I fix CVE-2025-32063?
Fixing CVE-2025-32063 involves reconfiguring the SSH server settings and ensuring that unnecessary developer features are disabled.
What impact does CVE-2025-32063 have on Infotainment ECU?
CVE-2025-32063 can potentially allow unauthorized remote access, disrupting vehicle security and functionality.
Which products are affected by CVE-2025-32063?
CVE-2025-32063 affects the BOSCH Infotainment ECU used in various vehicle models.
What are the symptoms of CVE-2025-32063 being exploited?
If CVE-2025-32063 is exploited, you may notice unexpected remote access to the Infotainment ECU and activation of developer features.