CVE-2025-32058
Unknown Unknown - Not Provided
Code Execution Vulnerability in Bosch RH850 ECU Enables CAN Attack

Publication date: 2026-02-15

Last updated on: 2026-02-15

Assigner: Automotive Security Research Group (ASRG)

Description
The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the infotainment main SoC to perform code execution on the RH850 module and subsequently send arbitrary CAN messages over the connected CAN bus. First identified on Nissan Leaf ZE1 manufactured in 2020.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-15
Last Modified
2026-02-15
Generated
2026-06-16
AI Q&A
2026-02-15
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
bosch infotainment_ecu *
bosch rh850 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Infotainment ECU manufactured by Bosch, which uses a RH850 module for CAN communication. The RH850 module is connected to the infotainment system via the INC interface using a custom protocol. During the processing of requests on this protocol on the V850 side, an attacker who already has code execution on the infotainment main SoC can exploit this vulnerability to gain code execution on the RH850 module.

Once the attacker has control over the RH850 module, they can send arbitrary CAN messages over the connected CAN bus, potentially manipulating vehicle systems.

Impact Analysis

This vulnerability can have severe impacts because it allows an attacker with initial access to the infotainment system to escalate their control to the RH850 module responsible for CAN communication.

  • The attacker can execute arbitrary code on the RH850 module.
  • They can send arbitrary CAN messages, potentially controlling or disrupting vehicle functions connected to the CAN bus.
  • This could lead to safety risks, unauthorized control of vehicle systems, or denial of service.
Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-32058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart