God Mode On: how we attacked a vehicle’s head unit modem
ID: 528dfc8c-2c58-5b51-9444-1a01d0313b3c
STIX ID: report--528dfc8c-2c58-5b51-9444-1a01d0313b3c
Feed Name: Securelist by Kaspersky
Date Published: 2025-12-16
Date Updated: 2026-04-29
Author: Alexander Kozlov, Sergey Anufrienko, Kaspersky ICS CERT
This report demonstrates a practical remote compromise of a Unisoc UIS7862A modem in a vehicle head unit: researchers found a stack-buffer overflow in the 3G RLC handler (CVE-2024-39432) enabling remote code execution on the modem, used ROP and MPU manipulation to gain persistence, and leveraged a hidden peripheral DMA for lateral movement to the application processor—ultimately allowing full SoC compromise and execution on the head unit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
