CVE-2025-34251: Tesla Telematics Control Unit (TCU) < v2025.14 Authentication Bypass
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port is exposed externally, an attacker with physical access can write an arbitrary file to a writable location and then overwrite the kernel’s ueventhelper or /proc/sys/kernel/hotplug entries via ADB, causing the script to be executed with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34251?
The severity of CVE-2025-34251 is classified as medium due to the potential for unauthorized access and control of the Tesla Telematics Control Unit.
How do I fix CVE-2025-34251?
To fix CVE-2025-34251, you should update the Tesla Telematics Control Unit firmware to version 2025.14 or later.
What products are affected by CVE-2025-34251?
CVE-2025-34251 affects the Tesla Telematics Control Unit firmware versions prior to v2025.14.
What type of vulnerability is CVE-2025-34251?
CVE-2025-34251 is classified as an authentication bypass vulnerability affecting the Android Debug Bridge on the Tesla Telematics Control Unit.
Can CVE-2025-34251 lead to remote exploitation?
Yes, CVE-2025-34251 can potentially allow remote exploitation through unauthorized access to the device via adb push/pull and adb forward.