Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-32057— Misconfigured SSL/TLS communication of Redbend service for Infotainment ECU

CVSS 6.5 · Medium EPSS 0.01% · P1
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-32057

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Misconfigured SSL/TLS communication of Redbend service for Infotainment ECU
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not verified. As a result, an attacker may be able to impersonate a Redbend backend server using a self-signed certificate. First identified on Nissan Leaf ZE1 manufactured in 2020.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
证书验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Bosch Infotainment ECU 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Bosch Infotainment ECU是德国Bosch公司的一个车载娱乐系统。 Bosch Infotainment ECU存在安全漏洞,该漏洞源于SSL引擎使用默认配置导致未验证服务器根证书,可能导致攻击者冒充Redbend后端服务器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
BoschInfotainment system ECU 283C30861E -

II. Public POCs for CVE-2025-32057

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-32057

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-32057

No comments yet


Leave a comment