CVE-2025-34251 - CVE House
Back to Database
Status published High CVE-2025-34251

Tesla Telematics Control Unit (TCU) < v2025.14 Authentication Bypass

Vulnerability Description

Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port is exposed externally, an attacker with physical access can write an arbitrary file to a writable location and then overwrite the kernel’s uevent_helper or /proc/sys/kernel/hotplug entries via ADB, causing the script to be executed with root privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34251

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Alex Plaskett and McCaulay Hudson of NCC Group

Affected Vendor

Affected Software

Telematics Control Unit (TCU)
Vulnerable Versions:
0

Timeline

Official Publish: October 6th, 2025
Last Modified: May 15th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)