CVE-2025-6785: Tesla Model 3 Physical CAN Bus Injection
Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle. Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6785?
CVE-2025-6785 is a critical vulnerability that allows for potential unauthorized control of vehicle functions.
How do I fix CVE-2025-6785?
To mitigate CVE-2025-6785, it is advised to secure the physical access to CAN wires and update to the latest vehicle software version.
Which vehicles are affected by CVE-2025-6785?
CVE-2025-6785 affects Tesla Model 3 vehicles running software versions from 2023.0 to below 2023.44.
What are the potential risks associated with CVE-2025-6785?
The primary risk of CVE-2025-6785 is the possibility of remote start functions being compromised, allowing unauthorized control of the vehicle.
Is there a patch available for CVE-2025-6785?
Yes, Tesla is expected to release a software update to address CVE-2025-6785, and users should ensure they are running the latest version.