Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
nvdmedium Β· 6.5
cve-2026-52852
Traccar, an open source GPS tracking system, has a flaw before version 6.14.0 where an authenticated user with group-management and report permissions can create a circular group hierarchy and then request a trips or stops report, causing the server to loop endlessly. This pins a web worker at high CPU even after the client disconnects and can exhaust the web/API worker pool if repeated, amounting to a denial-of-service condition. This could be relevant where Traccar is deployed in automotive or fleet-tracking systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.5
cve-2026-78227
NLnet Labs Unbound versions 1.22.0 through 1.26.1, when compiled with DNS-over-QUIC support, contain a use-after-free flaw in how a DNS response buffer is freed while a retransmission pointer still references it. An unauthenticated attacker who can query Unbound over DoQ can trigger the flaw by withholding acknowledgements, sending a stream reset, and waiting for a timeout, causing retransmissions against freed memory and eventually an abnormal server exit. This could be relevant where Unbound is deployed in automotive systems, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
csaf_siemensmedium Β· 6.5
ssa-823812
Siemens WTV676 and WTV776 devices contain a denial of service vulnerability because they do not properly validate input received from backend services. An unauthenticated remote attacker could exploit this to force the devices into protection mode, which disables remote connectivity functions such as Web Access. Siemens has released new versions and recommends updating to the latest versions.
nvdmedium Β· 6.5
cve-2026-55306
The advisory describes a denial-of-service vulnerability in the Cellular Modem component due to improper input validation, which a remote attacker could exploit without any additional execution privileges or user interaction. This could be relevant where cellular modem components are deployed in automotive systems, such as in telematics or connectivity units. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.5
cve-2026-15893
Zephyr's IPv6 Neighbor Discovery implementation is affected: a crafted, unauthenticated Router Advertisement with a Reachable Time of 1 causes the computed reachable time to become zero. An attacker with link-local adjacency can then trigger a fatal kernel assertion on builds with CONFIG_ASSERT enabled, or force reachable neighbors into perpetual re-solicitation on builds without it, resulting in a remote denial of service with availability-only impact. This could be relevant where Zephyr is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.5
cve-2026-14697
The advisory describes a denial-of-service vulnerability in the Zephyr operating system's IPv6 networking stack, where a flaw in the Neighbor Solicitation handling can permanently leak transmit packets, exhausting the system's limited TX pool and causing a complete network outage that persists until reboot. An on-link attacker can trigger this deterministically by sending a burst of spoofed packets, and the issue affects any device using Zephyr's IPv6 stack, which could be relevant in automotive systems if this component is deployed. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.5
cve-2026-14696
The advisory describes a denial-of-service vulnerability in the Zephyr networking stack when Ethernet bridging is enabled. An attacker on a bridged network segment can send unauthenticated broadcast or multicast frames with unrecognized EtherTypes, causing the device to leak receive buffers until its finite RX pool is exhausted, permanently blocking all incoming traffic until a reboot. The severity is a persistent denial of service with no confidentiality or integrity impact. This could be relevant where Zephyr is deployed in automotive systems, such as in-vehicle networking or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.5
cve-2026-13734
Zephyr's WireGuard VPN component has a vulnerability where replayed network packets are processed before the anti-replay check, allowing an attacker who captures valid traffic to redirect the victim's tunnel traffic to a spoofed address and disrupt the session. The issue affects the WireGuard data-plane handler in Zephyr's networking subsystem and is rated as an integrity and availability concern, though encrypted payloads remain protected. This could be relevant where Zephyr's WireGuard is deployed in automotive systems, such as in-vehicle networking or telematics; confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.5
cve-2026-81341
wolfEngine before version 1.4.1 has a vulnerability where it reuses the same AES-CCM encryption key and nonce across multiple TLS 1.2 and DTLS 1.2 records, which could allow an attacker to decrypt data and forge authentication tags, weakening confidentiality and integrity. The issue only affects wolfEngine, not wolfProvider, and requires AES-CCM cipher suites to be explicitly enabled, as they are not on by default. This could be relevant where wolfEngine is deployed in automotive systems, so confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.5
cve-2026-53583
This advisory affects libgit2, a software library used to add Git functionality to applications. A flaw in its OpenSSL security backend causes it to reject valid IP address certificates and accept invalid ones, allowing a network attacker with a trusted certificate to intercept connections to IP-literal HTTPS URLs. The issue is fixed in versions 1.8.6 and 1.9.5. This could be relevant where libgit2 is deployed in automotive systems, such as for software update or telematics functions. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.5
cve-2026-12632
Zephyr's Precision Time Protocol (PTP) message handling has a flaw where an unvalidated 4-bit message type from a network packet can cause an out-of-bounds read, potentially leading to a denial of service (crash) or limited memory corruption. This is triggered by an unauthenticated attacker on the same network link sending a crafted PTP frame to a device with PTP enabled. This could be relevant where Zephyr's PTP stack is deployed in automotive systems, such as in-vehicle networking or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.5
cve-2026-12631
The advisory describes a vulnerability in the Zephyr kernel, an open-source operating system for embedded devices. The flaw affects the validation of two system calls, k_thread_join() and k_thread_abort(), where an unprivileged user-mode thread can trigger a denial of service by crashing the kernel, or potentially bypass access controls to manipulate unauthorized threads. The severity is high, as it allows a locally triggerable crash or access-control bypass. This could be relevant where Zephyr is deployed in automotive systems, such as in vehicle control units or infotainment. Confirm applicability through the product SBOM or dependency inventory.
csaf_codesysgmbhmedium Β· 6.5
vde-2026-041
This vulnerability affects the PROFINET industrial protocol stack used in automotive manufacturing plants and assembly lines for PLC-based production equipment. An unauthenticated attacker on the same network can send malformed data to crash the PLC application, causing a controlled stop that halts production until the system is manually restarted. The risk is limited to denial of service rather than remote code execution, and CODESYS recommends updating to version 4.8.0.0 along with network segmentation and firewall protections.
fkie_nvdmedium Β· 6.5
cve-2026-47180
This vulnerability affects the mDNS (multicast DNS) service discovery protocol used in automotive infotainment systems, over-the-air update mechanisms, and in-vehicle network service discovery. An unauthenticated attacker on the same local network can send a specially crafted mDNS packet that triggers a recursion error, causing sustained CPU overload, log flooding, and degradation of mDNS-dependent features like media streaming and device discovery. The issue is rated as high severity because it can disrupt critical vehicle services without authentication, but it is limited to local network access and is fixed in version 0.149.5.
fkie_nvdmedium Β· 6.5
cve-2026-13699
This vulnerability affects the Eclipse KUKSA Databroker, which is a vehicle data broker component used in automotive software architectures for managing and distributing vehicle signals and data between ECUs and applications. An attacker with a valid JWT token can send a specially crafted gRPC request that omits a required data field, causing the server to crash and cancel the connection, though the system remains available for other requests. This is a medium-severity issue that requires valid authentication to exploit, limiting the attack surface to authorized users or compromised credentials.
nvdmedium Β· 6.4
cve-2026-56988
A use-after-free race condition exists in multiple functions of bluetooth_cco.cc, which could allow an attacker with local access and System execution privileges to escalate privileges without any user interaction. This could be relevant where this Bluetooth component is deployed in automotive systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5medium Β· 6.4
cve-2026-14366
The Silicon Labs SiWx917 WiFi driver contains a bug where it incorrectly frees a network packet that belongs to the Zephyr networking stack, leading to use-after-free and double-free conditions that can corrupt the shared packet pool. An adjacent attacker on the same WiFi network could trigger this by inducing ordinary transmissions, potentially causing crashes, transmit hangs, and memory corruption, with the primary impact being loss of availability. This could be relevant where the SiWx917 WiFi driver is deployed in automotive systems, such as in-vehicle connectivity modules, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
fkie_nvdmedium Β· 6.4
cve-2026-13305
This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems, specifically the Autel MaxiCharger AC Elite Home EV charger. A physically present attacker can exploit the lack of proper cryptographic signature verification during software updates to install malicious code on the device without needing any authentication. This is a critical flaw that could allow an attacker to take full control of the charger, potentially disrupting charging operations or using the device as a foothold for further attacks.
csaf_abbmedium Β· 6.4
9akk108472a9270
This vulnerability affects the KNX building automation bus system used in smart building and industrial control networks, which can be found in automotive manufacturing plants and assembly lines for controlling lighting, HVAC, and access systems. An attacker with physical access to the bus could tamper with firmware updates to make devices unusable or alter their behavior, but ABB has no plans to fix the issue because it only impacts legacy devices that lack modern security features. The risk is limited to environments where unauthorized personnel can physically reach the control network, making it a low-severity threat for properly secured facilities.
nvdmedium Β· 6.3
cve-2026-81871
OpenTelemetry-Go versions before 0.21.0 have a flaw in the gRPC log exporter where TLS client certificates configured through environment variables are not applied, so mutual TLS and private CA pinning can be bypassed. A network attacker who can intercept or spoof the collector connection using a system-trusted certificate could read or alter log telemetry. This could be relevant where OpenTelemetry-Go is deployed in automotive systems, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.3
cve-2026-73169
Advantech EKI-1242EIMS firmware V1.06.01 contains a stored cross-site scripting flaw in its Modbus transaction management interface, which a remote authenticated attacker could exploit to plant malicious script that runs in an administrator's browser when they open the affected management page. The advisory rates this as a CWE-79 issue, though it does not state a numeric severity score. This could be relevant where the EKI-1242EIMS is deployed in automotive or industrial systems; confirm applicability through the product SBOM or dependency inventory.
nvdmedium Β· 6.1
cve-2026-18495
A heap-buffer overflow exists in the libtiff tiff2pdf utility, where a crafted BigTIFF file causes a 64-bit StripByteCounts value to be truncated to 32 bits, leading to an undersized memory allocation and an out-of-bounds copy. An attacker can exploit this to cause a crash and severe memory corruption. This could be relevant where libtiff is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
csaf_siemensmedium Β· 6.1
ssa-157465
A reflected cross-site scripting vulnerability exists in the authentication redirect flow of Teamcenter, where an unauthenticated remote attacker can inject malicious JavaScript into an authenticated user's browser session by tricking them into clicking a crafted URL. Successful exploitation could allow the attacker to read data or perform actions within the victim's Teamcenter session. Siemens has released updated versions to address this issue, and the advisory does not establish a direct automotive connection, so confirm applicability through the product SBOM or dependency inventory if Teamcenter is used in automotive systems.
nvdmedium Β· 6.1
cve-2026-13216
The advisory describes a security flaw in Zephyr's virtio PCI driver, where a device-supplied length value is not properly validated, allowing an attacker-controlled device to write data beyond a fixed memory buffer on the kernel stack. This could lead to a system crash or potential code execution, with severity implied as high due to kernel-mode memory corruption. The affected component is the virtio PCI driver, which is used in embedded systems and could be relevant where Zephyr runs on bare metal with untrusted or physical virtio devices, or in confidential-computing setups; this is not confirmed to affect vehicles directly. Confirm applicability through the product SBOM or dependency inventory.
csaf_siemensmedium Β· 6.1
ssa-127084
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the Fortigate next-generation firewall integrated into Siemens RUGGEDCOM APE1808 devices used for network security in industrial environments. An authenticated remote attacker could exploit cross-site scripting or path traversal flaws to execute malicious code or delete critical file system data on the firewall, potentially disrupting network security and operations across connected manufacturing systems. The severity is high, as successful exploitation could compromise the integrity of industrial networks, though Siemens notes that physical access is required for the most destructive file deletion attack.