CVE Feed

    Dashboard / CVE / CVE-2025-34251

    CVE-2025-34251

    Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port is exposed externally, an attacker with physical access can write an arbitrary file to a writable location and then overwrite the kernel’s uevent_helper or /proc/sys/kernel/hotplug entries via ADB, causing the script to be executed with root privileges.

    Published:Oct 6, 2025
    Last Modified:Apr 15, 2026
    EPS:Oct 6, 2025
    EPSS Score:0.00044
    CVSS Score:8.6

    Affected Products

    Vendor
    Google
    Product
    Android
    Vendor
    Tesla
    Product
    Telematics Control Unit
    Vendor
    Tesla
    Product
    Tesla
    Vendor
    Tesla
    Product
    Tesla Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High