logo

Technical Advisory: Tesla Telematics Control Unit - ADB Auth Bypass

ID: 69f29d6d-af51-5ad2-bdff-5cb6286c49e1

STIX ID: report--69f29d6d-af51-5ad2-bdff-5cb6286c49e1

Feed Name: NCC Research

Threat Score
55/100

Date Published: 2025-12-02

Date Updated: 2026-08-03

...
...

This NCC Group advisory describes a vulnerability in Tesla TCU firmware (observed on v12 / 2025.2.6) where ADB running as root could be abused via adb pull/push and the kernel uevent_helper/hotplug interfaces to execute an attacker-supplied script as root, providing a local attacker with physical access to the vehicle a root shell on the TCU; Tesla mitigated the issue in 2025.14 by disabling adbd on the Micro USB interface and updating launch_adbd logic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.