Vulnerability Report

CVE-2025-2082

RCE

Title: Tesla Model 3 RCE

Memory Corruption

Proof Of Concept

PoC Available for CVE-2025-2082

CWE Category CWE-190
Published Date Apr 30, 2025
Modified Date Aug 12, 2025
Exploit Status Available
Score 7.5 CVSS v3.0
Exploit Probability (EPSS)
0.37%

Vulnerability Summary

CVE-2025-2082: Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. Authentication is not required to exploit this vulnerability. The specific flaw exists within the VCSEC module. By manipulating the certificate response sent from the Tire Pressure Monitoring System (TPMS), an attacker can trigger an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the VCSEC module and send arbitrary messages to the vehicle CAN bus. Was ZDI-CAN-23800.

CVSS v3.0
Source Entity [email protected]
Severity HIGH
7.5
Attack Vector
ADJACENT_NETWORK
Complexity
HIGH
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2025-2082 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/Burak1320demiroz/cve-2025-2082
View Code
GitHub https://github.com/shirabo/cve-2025-2082-POV
View Code
MODIFIED

Vulnerability data or affected products updated.

MODIFIED

Vulnerability data updated via NVD.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector ADJACENT_NETWORK
Complexity HIGH
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Stack

No specific products linked.