Mercedes-Benz Head Unit security research report
ID: 7e199c1e-2a80-5bc4-8be2-1d4af27a89cf
STIX ID: report--7e199c1e-2a80-5bc4-8be2-1d4af27a89cf
Feed Name: Securelist by Kaspersky
This research analyzes the Mercedes‑Benz MBUX head unit (first generation) and documents numerous security flaws across diagnostics, firmware update handling, custom IPC frameworks and USB import/export features. The report details practical exploitation techniques—including stack/heap overflows, command injection into iptables handling, and local privilege escalation via an outdated Polkit—demonstrates how these can lead to service crashes, arbitrary file writes and privilege gains, and lists multiple assigned CVEs disclosed to the vendor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
