Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.

1962advisories found
Clear filters
Results
nvdhigh · 8.6

cve-2026-73170

Advantech EKI-1242EIMS firmware V1.06.01 contains a code injection flaw (CWE-94) in its Modbus CSV import workflow, which a remote authenticated attacker could exploit by importing a crafted file to execute arbitrary Lua code on the device. This could be relevant where the EKI-1242EIMS is deployed in automotive or industrial systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-73167

Advantech EKI-1242IEIMS firmware V1.06.01 contains an OS command injection flaw in its web management interface, which a remote authenticated attacker could exploit to run arbitrary commands as root. This could be relevant where the Advantech EKI-1242IEIMS is deployed in automotive systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-73166

The advisory describes a code injection vulnerability in the web management interface of Advantech EKI-1242IEIMS firmware V1.06.01, which allows a remote authenticated attacker to execute arbitrary code on the device, including OS commands as root. This could be relevant where this device is deployed in automotive systems, such as industrial networking in automotive manufacturing environments. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-73165

Advantech EKI-1242IEIMS firmware V1.06.01 contains an OS command injection flaw in its web management interface, which a remote authenticated attacker could exploit to run arbitrary commands as root. This could be relevant where the Advantech EKI-1242IEIMS is deployed in automotive systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-73164

Advantech EKI-1242IEIMS firmware V1.06.01 contains an OS command injection flaw in its web management interface, which a remote authenticated attacker could exploit to run arbitrary commands as root. This could be relevant where the Advantech EKI-1242IEIMS is deployed in automotive systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-73163

Advantech EKI-1242IEIMS firmware V1.06.01 contains an OS command injection flaw in its web management interface, which a remote authenticated attacker could exploit to run arbitrary commands as root. This could be relevant where the Advantech EKI-1242IEIMS is deployed in automotive systems, though the advisory does not confirm an automotive connection. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-19535

Advantech EKI-1242IEIMS firmware V1.06.01 contains a cross-site request forgery flaw in its LuCI administrative web interface, which could let a remote unauthenticated attacker make unauthorized state-changing requests as a logged-in administrator, potentially gaining access to privileged management functions. The advisory does not confirm an automotive deployment, so this could be relevant where the affected Advantech device is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

csaf_trumpfsecokghigh · 8.6

vde-2026-091

TRUMPF products listed in the advisory bundle a vulnerable Wibu CodeMeter Runtime for Windows that carries several flaws, including privilege escalation, remote command execution, crashes, and unauthorized license-information disclosure. An attacker could delete arbitrary files with System privileges, take over CodeMeter WebAdmin, crash the runtime, or read another session's license data. The advisory does not state a numeric severity score.

csaf_abbhigh · 8.6

3bhs973333

ABB's AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah products are affected by multiple publicly disclosed vulnerabilities in the Wibu CodeMeter licensing component they use. An attacker with network access to an affected node could delete arbitrary files with system privileges, read or overwrite configuration data (including WebAdmin credentials), crash CodeMeter, or read sensitive license and memory information; several of these issues only apply when CodeMeter Runtime is configured as a server, which is not the default. ABB states it had no reports of these vulnerabilities being exploited at the time the advisory was issued.

csaf_abbhigh · 8.6

2nga003144

ABB has disclosed high-severity vulnerabilities in the WIBU CodeMeter Runtime component used for licensing in its zenon Software Platform. An attacker could exploit these flaws to gain elevated privileges on Windows systems, remotely access or modify sensitive configuration data, or crash the licensing service, potentially causing unauthorized access or service disruption. This is directly relevant to automotive operations because ABB zenon is used in industrial automation, so confirm applicability through the product SBOM or dependency inventory.

csaf_siemenshigh · 8.6

ssa-517424

SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability in their embedded HTTP server, which could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system, potentially exposing sensitive data like credentials and configuration secrets. Siemens has released updated versions to address this issue and recommends updating. This is directly relevant to automotive manufacturing environments where these fleet and plant management products are deployed.

csaf_sickhigh · 8.6

sca-2026-0011

Several vulnerabilities in the Wibu Systems CodeMeter Runtime affect multiple SICK products, including Sentio Creator, Sentio Compose, Safety Designer, Stream Editor, PLB, and several SICK Industrial PCs that ship with the runtime preinstalled. An attacker could exploit these flaws to delete arbitrary files with system privileges, crash the CodeMeter service, disclose sensitive information, or take over the CodeMeter WebAdmin, potentially impacting the integrity, confidentiality, and availability of the affected products. The severity is assessed using CVSS v3.1, with the final score depending on the customer's environment.

nvdhigh · 8.6

cve-2026-14947

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is affected by a high-severity vulnerability where a remote attacker with high privileges can upload a malicious ZIP file containing directory traversal sequences, allowing file writes to arbitrary server locations and potentially achieving arbitrary code execution, which could lead to full system compromise. This could be relevant where FDS102 is deployed in automotive systems, such as rail or road transport infrastructure. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.6

cve-2026-8989

This vulnerability affects the NXP i.MX6 chipset used in Autel MaxiCharger Single EV charging stations, where the hardware recovery pins are left exposed. An attacker with physical access can boot their own code, extract or modify the charger's firmware and sensitive data. This is a critical physical security flaw that could allow an attacker to compromise the charging station's operation and potentially spread malicious code to connected vehicles or networks.

nvdhigh · 8.6

cve-2026-8988

This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems. An attacker with physical access to the Autel MaxiCharger Single can interrupt the boot process via an exposed UART interface to access the bootloader, then modify the configuration or file system to gain full operating system access. This is a high-severity issue because it could allow an attacker to compromise the charger's security, potentially disrupting charging operations or accessing connected networks.

fkie_nvdhigh · 8.6

cve-2026-15720

This vulnerability affects the 5G core network software Open5GS, which is used in some connected vehicle telematics and fleet management systems for cellular communication. An attacker could exploit a memory read flaw in the authentication process to crash the network function, potentially disrupting service for all connected vehicles on that network. The severity is high as it could cause a widespread denial of service for subscribers.

cvelistv5high · 8.5

cve-2026-74860

A flaw exists in libxml2 when its Python bindings are enabled, where a remote attacker can send a specially crafted XML document with a DTD containing enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, leading to a denial of service through a reproducible crash in Python applications using these bindings. The advisory lists affected Red Hat Enterprise Linux and OpenShift products, and while no automotive connection is confirmed, this could be relevant where libxml2 is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.5

cve-2026-70628

This vulnerability affects the embedded Linux/Android Automotive software foundation used in infotainment and digital cockpit systems, where FFmpeg is commonly deployed for media playback of video files. An attacker could exploit a heap buffer overflow in the DVB subtitle parser by supplying a malicious WTV file, potentially achieving memory corruption or arbitrary code execution on the affected system. The severity is high, as it could compromise the infotainment unit’s integrity, though exploitation requires the attacker to deliver a crafted media file to the vehicle.

cvelistv5high · 8.5

cve-2026-70632

This vulnerability affects the Linux/Android Automotive software foundation used in infotainment and digital cockpit systems, where FFmpeg handles video playback from USB drives or media streaming. An attacker can exploit a heap out-of-bounds write in the GoPro CineForm HD decoder by crafting a malicious AVI file, potentially corrupting memory and achieving arbitrary code execution on the vehicle’s infotainment unit. The severity is high, as it could allow remote compromise of the system if a user plays a malicious file, though it requires user interaction and is limited to FFmpeg versions before 9.0.

fkie_nvdhigh · 8.5

cve-2026-60122

This GPS/GNSS vulnerability affects the gpsd software used in navigation, fleet tracking, and usage-based insurance telematics in connected vehicles, specifically the gpsprof utility that processes satellite data. An attacker who can inject malicious GPS data into a vehicle's navigation system could exploit this flaw to execute arbitrary operating system commands on the infotainment or telematics unit by embedding commands in the satellite "used" field, which gets processed by gnuplot. This is a critical code injection vulnerability that could allow an attacker to take full control of the affected system, potentially compromising vehicle safety and privacy.

nvdhigh · 8.4

cve-2026-42805

A stack-based buffer overflow exists in the Bosch Sensortec BHI385 SensorAPI C library, specifically in the debug message parser function bhi385_parse_debug_message, which copies attacker-controlled payload data into a fixed 17-byte stack buffer without validating the length value. A malicious or compromised sensor or bus participant could exploit this to crash firmware, cause a denial of service, or potentially execute arbitrary code through stack corruption. This could be relevant where the BHI385 SensorAPI is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.4

cve-2026-20502

The advisory describes a vulnerability in the vdec component of MediaTek chipsets, where a missing bounds check could allow an out-of-bounds write. An attacker could exploit this to achieve local escalation of privilege without needing additional execution privileges or user interaction. This could be relevant where MediaTek chipsets are deployed in automotive systems, and the stated severity is not explicitly provided in the advisory. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.4

cve-2026-20501

The advisory describes a heap buffer overflow in the vdec component of MediaTek chipsets, which could allow a local attacker to escalate privileges without needing user interaction or additional execution privileges. This could be relevant where MediaTek chipsets are deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.4

cve-2026-71969

This vulnerability affects OP-TEE, the trusted execution environment operating system used in vehicle ECUs, secure gateways, and key management systems across multiple automotive platforms. A malicious Trusted Application could exploit a buffer underwrite in RSA encryption operations to corrupt secure-world memory, potentially allowing an attacker to compromise critical security functions like secure boot, key storage, or vehicle authentication. The severity is high because it requires a malicious app already running in the trusted environment, but successful exploitation could undermine the entire security foundation of affected vehicle systems.

cvelistv5high · 8.4

cve-2026-8718

Zephyr is the real-time operating system deployed in vehicle ECUs, ADAS controllers, and body control modules, and this vulnerability affects its DTLS networking stack used for secure vehicle-to-cloud communications. An unprivileged attacker with access to a connected DTLS socket could trigger a kernel-heap buffer overflow by passing a small buffer size, potentially allowing them to corrupt memory or crash the system. This is a high-severity issue that requires an established DTLS session with Connection ID enabled, and the fix rejects undersized buffers to prevent the overflow.