CVE-2025-32058
Last modified
CVE-2025-32058 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the infotainment main SoC to perform code execution on the RH850 module and subsequently send arbitrary CAN messages over the connected CAN bus. First identified on Nissan Leaf ZE1 manufactured in 2020.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-32058?
How severe is CVE-2025-32058?
How do I fix CVE-2025-32058?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-32051A flaw was found in libsoup. The libsoup soup_uri_decode_dat…5.9
- CVE-2025-32052A flaw was found in libsoup. A vulnerability in the sniff_un…6.5
- CVE-2025-32053A flaw was found in libsoup. A vulnerability in sniff_feed_o…6.5
- CVE-2025-32054In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source co…3.3
- CVE-2025-32056The anti-theft protection mechanism can be bypassed by attac…4
- CVE-2025-32057The Infotainment ECU manufactured by Bosch which is installe…6.5
- CVE-2025-32059The specific flaw exists within the Bluetooth stack develope…8.8
- CVE-2025-3206A vulnerability has been found in code-projects Hospital Man…7.5
- CVE-2025-32060The system suffers from the absence of a kernel module signa…6.7
- CVE-2025-32061The specific flaw exists within the Bluetooth stack develope…8.8
- CVE-2025-32062The specific flaw exists within the Bluetooth stack develope…8.8
- CVE-2025-32063There is a misconfiguration vulnerability inside the Infotai…6.8
Are you affected by CVE-2025-32058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
