Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.
1962advisories found
csaf_phoenixcontactgmbhcokgcritical · 9.8
vde-2026-008
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems, specifically the Phoenix Contact CHARX SEC-3xxx series charging controllers. An unauthenticated remote attacker can exploit multiple flaws—including missing authentication on the MQTT broker, command injection, and privilege escalation—to fully compromise the device, potentially interrupting charging operations, stealing data, or installing malicious firmware. The severity is critical, as these vulnerabilities can lead to a complete loss of confidentiality, integrity, and availability, though Phoenix Contact recommends using the devices only in closed networks with firewalls until firmware version 1.9.1 is released.
csaf_weidmuellerinterfacegmbhcokgcritical · 9.8
vde-2026-085
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the PROCON-WEB SCADA software used for monitoring and controlling production equipment. An unauthenticated attacker on the network can exploit a SQL injection flaw to read, modify, or delete data and execute arbitrary commands, potentially disrupting vehicle assembly operations. Weidmueller strongly recommends updating to version 6.11.3 and limiting network exposure to trusted systems.
fkie_nvdcritical · 9.8
cve-2026-16462
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the PROCON-WEB SCADA system's 'GetGridData' endpoint. An unauthenticated attacker can remotely execute arbitrary SQL commands, potentially allowing them to steal sensitive production data, manipulate manufacturing processes, or disrupt assembly line operations. This is a critical severity issue that could halt vehicle production or cause quality defects across multiple vehicle models.
csaf_ncscnlcritical · 9.8
ncsc-2026-0256
This vulnerability affects Oracle Communications products, which are used in telecom networks that can support connected vehicle services like fleet management and emergency call systems. An attacker could exploit these flaws to fully take over the server, execute malicious code, or steal sensitive data, with the most critical issues allowing a complete system compromise without needing a password. The risk is high, as 12 of the 213 fixed vulnerabilities have a severity score of 9 or higher out of 10.
fkie_nvdcritical · 9.8
cve-2026-64620
This vulnerability affects the Remote Desktop Protocol (RDP) stack used in some automotive diagnostic tools and remote vehicle access systems that rely on RDP for technician connectivity. An unauthenticated attacker can send a specially crafted message to overflow a heap buffer before authentication, potentially causing a denial of service that could disrupt remote diagnostics or fleet management operations. The severity is high because it requires no credentials and can crash the RDP service, though it does not directly impact vehicle driving controls.
csaf_siemenscritical · 9.8
ssa-734552
This vulnerability affects the OpenSSL cryptographic library used in Siemens Desigo CC building management systems, which can also be deployed in automotive manufacturing plants and industrial facilities for environmental control and energy management. A remote attacker could send a specially crafted message to trigger a stack buffer overflow, potentially causing a system crash or allowing them to execute malicious code on the affected device. Siemens has released software updates to fix this issue, and strongly recommends applying them as soon as possible to prevent potential disruption to facility operations.
csaf_siemenscritical · 9.8
ssa-019113
This vulnerability affects the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP, which is a specialized industrial controller used in automotive manufacturing plants and assembly lines for programmable logic control. Multiple flaws in the embedded Linux kernel and OpenSSH components could allow an attacker with local or network access to escalate privileges, cause system crashes, or leak sensitive information. Siemens is preparing fixes and recommends protecting network access to these devices as a security measure.
csaf_siemenscritical · 9.8
ssa-470355
This vulnerability affects CADRA, a Siemens engineering software used in automotive manufacturing plants for design and production processes. Multiple flaws in the zlib compression library and Foxit PDF components could allow an attacker to crash the software or potentially execute malicious code by sending a specially crafted file. Siemens has released an updated version to fix these issues, and given the critical role of CADRA in vehicle production, immediate updating is strongly recommended to prevent disruptions on the factory floor.
csaf_siemenscritical · 9.8
ssa-585531
This vulnerability affects the SIDIS Secured SmartPlug, an industrial smart plug used in automotive manufacturing plants and assembly lines for secure power management of production equipment. Multiple flaws in OpenSSL, OpenSSH, and other components could allow an attacker to crash the device, execute malicious code, or intercept communications, with the most severe issues enabling remote code execution. Siemens has released version V7.26.0310 to fix these problems, and updating immediately is strongly recommended.
nvdcritical · 9.5
cve-2026-8986
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems. A malicious or compromised OCPP server can send a crafted diagnostics request to the Autel MaxiCharger Single, allowing an attacker to execute arbitrary commands on the charging station. This is a critical vulnerability that could allow an attacker to take full control of the charger, potentially disrupting charging services or using the device as a foothold for further attacks.
csaf_sickcritical · 9.4
sca-2026-0010
SICK ICR890-4 and InspectorP6xx industrial devices contain a vulnerability in their SOPAS FileSystemAccess method that allows unintended remote access to internal virtual filesystem paths. An unauthenticated attacker with network access could exploit this to modify internal storage, configuration files, and system directories, potentially causing denial of service, unauthorized configuration changes, or disclosure of sensitive information. The advisory does not specify a CVSS severity score, but recommends minimizing network exposure and restricting access to mitigate the risk.
nvdcritical · 9.4
cve-2026-8987
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems. An authenticated attacker can exploit a heap overflow in the Autel MaxiCharger Single firmware to crash the device or potentially run malicious code, posing a serious risk to charging operations and network security.
nvdcritical · 9.3
cve-2026-73172
Advantech EKI-1242EIMS devices running firmware V1.06.01 contain an OS command injection flaw in the edgserver management service, which a remote unauthenticated attacker could exploit by sending crafted requests to TCP port 5058 to execute arbitrary commands as root. This could be relevant where such devices are deployed in automotive or industrial systems. Confirm applicability through the product SBOM or dependency inventory.
nvdcritical · 9.3
cve-2026-84696
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles. This could be relevant where the PS3111-S11 controller is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdcritical · 9.3
cve-2026-55068
The advisory describes a vulnerability in free5GC, an open-source 5G core network implementation, where the Network Repository Function (NRF) fails to validate incoming network function profiles. An attacker with access to the service-based interface could submit malicious profiles, poisoning the registry to redirect control-plane signaling, potentially exposing credentials, disrupting service discovery, and causing denial of service across network functions. The issue affects versions 4.2.2 and earlier, with a fix available in version 4.2.3. This could be relevant where free5GC is deployed in automotive systems, such as for vehicle-to-everything or private 5G networks; confirm applicability through the product SBOM or dependency inventory.
cvelistv5critical · 9.3
cve-2026-77234
Improper input validation in FreeRTOS-Kernel before version 11.3.1 could allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context, potentially leading to full system compromise. The advisory recommends upgrading to version 11.3.1 or later to remediate the issue. This could be relevant where FreeRTOS-Kernel is deployed in automotive systems, such as in embedded control units, and the severity is significant due to the privilege escalation risk; confirm applicability through the product SBOM or dependency inventory.
cvelistv5critical · 9.3
cve-2025-13293
This vulnerability affects the cellular baseband and telematics hardware used in TBEA TLogger devices, which are communication boxes deployed in electric vehicle charging and energy management systems. An attacker can exploit a hard-coded root password to gain full administrative control over the device via its exposed SSH service, allowing them to tamper with charging operations, steal data, or disrupt grid connectivity. The severity is critical because it requires no authentication and grants complete remote control, potentially impacting fleet operations and charging infrastructure reliability.
nvdcritical · 9.2
cve-2026-92943
AWS IoT Device SDK for Python versions 1.5.3 through 1.6.0 on Python 3.7 and later contain improper certificate validation with host mismatch in the MQTT client TLS connection layer. An adversary-in-the-middle actor could impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, using a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. The advisory does not state a severity rating; upgrading to version 1.6.1 remediates the issue. This could be relevant where the AWS IoT Device SDK for Python is deployed in automotive systems, for example in connected-vehicle telematics or EV-charging backends that use AWS IoT Core. Confirm applicability through the product SBOM or dependency inventory.
nvdcritical · 9.2
cve-2026-3869
A CWE-303 authentication algorithm implementation flaw exists in Schneider Electric Modicon M580 and Modicon M580 Safety PLCs, and it could cause loss of confidentiality, integrity and availability of the PLC when an application project with a lower application level is running on it. This could be relevant where these PLCs are deployed in automotive manufacturing or industrial control systems. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5critical · 9.2
cve-2026-67367
SIMOVE Fleetmanager and SIPLANT are affected by a vulnerability in their embedded HTTP server that fails to block directory traversal, allowing an unauthenticated remote attacker to read arbitrary files from the underlying operating system, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets. The advisory does not confirm automotive deployment, but these products could be relevant where they are used in automotive or industrial fleet-management systems. Confirm applicability through the product SBOM or dependency inventory.
fkie_nvdcritical · 9.2
cve-2026-49035
This cellular baseband vulnerability affects the 4G/5G modems used in telematics control units and eCall systems. An attacker could exploit a heap-based buffer overflow by sending a specially crafted MMS Initiate request, potentially achieving remote code execution if memory protections are disabled, or causing a denial of service otherwise. This is a critical issue that could allow remote compromise of vehicle communication systems.
csaf_abbcritical · 9.1
4jde002044
ABB's dynovaPRO product contains a flaw in its Keycloak authentication component that lets an unauthenticated attacker remotely hijack user accounts by abusing the "Forgot Password" function, requiring only the victim's email address. Successful exploitation could give an attacker control over user accounts and, depending on privileges, unauthorized access to data, system configuration changes, and control commands affecting operational devices such as chargers, batteries, and PV systems. ABB has deployed a cloud-side fix, blocked and forced password resets for potentially affected users, and states it had no confirmed reports of active exploitation as of August 27, 2026.
cvelistv5critical · 9.1
cve-2026-90647
The advisory describes an improper certificate validation flaw in the IEC 60870-5-104 TLS client of ASE/Kalkitech ASE2000 V2 Communication Test Set versions 2.35 through 2.37 on Windows, which a network-positioned attacker could exploit to bypass certificate validation and conduct a Man-in-the-Middle attack on protected communications. The advisory does not state a severity rating. This could be relevant where such communication test equipment is deployed in automotive or industrial systems; confirm applicability through the product SBOM or dependency inventory.
csaf_siemenscritical · 9.1
ssa-503852
Industrial Edge Management contains an authentication bypass vulnerability in its identity management component that lets an unauthenticated remote attacker reset user credentials without completing email verification, potentially leading to full account takeover. Siemens has released updated versions to fix this issue and recommends updating. This advisory does not explicitly state an automotive connection, so this could be relevant where Industrial Edge Management is deployed in automotive manufacturing or related systems; confirm applicability through the product SBOM or dependency inventory.
csaf_mettlertoledogmbhcritical · 9.1
vde-2026-088
METTLER TOLEDO's LabX Standard software versions 21.3.22 through 21.4.23 contain multiple vulnerabilities, including denial-of-service, authentication bypass, memory corruption, and potential remote code execution. Three specific vulnerabilities are fixed in version 21.4.25, while others await future releases. This could be relevant where LabX Standard is deployed in automotive laboratory or manufacturing environments, so confirm applicability through the product SBOM or dependency inventory.