CVE-2025-34251
Last modified
CVE-2025-34251 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port is exposed externally, an attacker with physical access can write an arbitrary file to a writable location and then overwrite the kernel’s uevent_helper or /proc/sys/kernel/hotplug entries via ADB, causing the script to be executed with root privileges.
Metrics
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-34251?
How severe is CVE-2025-34251?
How do I fix CVE-2025-34251?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34246Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34247Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQ…6.5
- CVE-2025-34248D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a…7.2
- CVE-2025-34249Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-3425The IntelliSpace portal application utilizes .NET Remoting f…7.3
- CVE-2025-34250Rejected reason: This CVE ID was rejected because it was res…
- CVE-2025-34252Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34253D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.4
- CVE-2025-34254D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.3
- CVE-2025-34255D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain …5.3
- CVE-2025-34256Advantech WISE-DeviceOn Server versions prior to 5.4 contain…9.8
- CVE-2025-34257Advantech WISE-DeviceOn Server versions prior to 5.4 contain…5.4
Are you affected by CVE-2025-34251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
