CVE-2025-6785
Last modified
CVE-2025-6785 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle. Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functions of the vehicle. Testing completed on Tesla Model 3 vehicles with software version v11.1 (2023.20.9 ee6de92ddac5). This issue affects Model 3: With software versions from 2023.Xx before 2023.44.
Metrics
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:L/U:Amber
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6785?
How severe is CVE-2025-6785?
How do I fix CVE-2025-6785?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67844The GitHub Integration API in Mintlify Platform before 2025-…4.3
- CVE-2025-67845A Directory Traversal vulnerability in the Static Asset Prox…5.4
- CVE-2025-67846The Deployment Infrastructure in Mintlify Platform before 20…6.5
- CVE-2025-67847A flaw was found in Moodle. An attacker with access to the r…8.8
- CVE-2025-67848A flaw was found in Moodle. This authentication bypass vulne…8.1
- CVE-2025-67849A flaw was found in Moodle. This cross-site scripting (XSS) …6.1
- CVE-2025-67850A flaw was found in moodle. This vulnerability, known as Cro…6.1
- CVE-2025-67851A flaw was found in moodle. This formula injection vulnerabi…7.8
- CVE-2025-67852A flaw was found in Moodle. An open redirect vulnerability i…6.1
- CVE-2025-67853A flaw was found in Moodle. A remote attacker could exploit …7.5
- CVE-2025-67855A flaw was found in mooodle. A remote attacker could exploit…6.1
- CVE-2025-67856A flaw was found in Moodle. An authorization logic flaw, spe…9.8
Are you affected by CVE-2025-6785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
