logo

Cinterion EHS5 3G UMTS/HSPA Module Research

ID: b93599c5-cc36-5d79-b46c-725b417fc71d

STIX ID: report--b93599c5-cc36-5d79-b46c-725b417fc71d

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2024-06-13

Date Updated: 2026-04-29

Author: Kaspersky ICS CERT

...
...

Kaspersky researchers analyzed Telit Cinterion EHSx-series modems and discovered multiple security flaws—seven local and one remote—that include a heap-based buffer overflow in the ULP (SUPL) message handling. Using crafted SMS messages and filesystem/MIDlet manipulation, they achieved remote code execution on the modem, activated OTAP, installed a manufacturer-privileged MIDlet, and used the modem foothold to pivot into a truck’s telematics and vehicle ECUs, demonstrating the potential for complete vehicle takeover; vendor disclosure and mitigation recommendations are provided, though some devices may remain unpatchable due to integration constraints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.