CVE-2025-32058
Unknown Unknown - Not Provided
Code Execution Vulnerability in Bosch RH850 ECU Enables CAN Attack

Publication date: 2026-02-15

Last updated on: 2026-02-15

Assigner: Automotive Security Research Group (ASRG)

Description
The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the infotainment main SoC to perform code execution on the RH850 module and subsequently send arbitrary CAN messages over the connected CAN bus. First identified on Nissan Leaf ZE1 manufactured in 2020.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-15
Last Modified
2026-02-15
Generated
2026-05-27
AI Q&A
2026-02-15
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
bosch infotainment_ecu *
bosch rh850 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Infotainment ECU manufactured by Bosch, which uses a RH850 module for CAN communication. The RH850 module is connected to the infotainment system via the INC interface using a custom protocol. During the processing of requests on this protocol on the V850 side, an attacker who already has code execution on the infotainment main SoC can exploit this vulnerability to gain code execution on the RH850 module.

Once the attacker has control over the RH850 module, they can send arbitrary CAN messages over the connected CAN bus, potentially manipulating vehicle systems.


How can this vulnerability impact me? :

This vulnerability can have severe impacts because it allows an attacker with initial access to the infotainment system to escalate their control to the RH850 module responsible for CAN communication.

  • The attacker can execute arbitrary code on the RH850 module.
  • They can send arbitrary CAN messages, potentially controlling or disrupting vehicle functions connected to the CAN bus.
  • This could lead to safety risks, unauthorized control of vehicle systems, or denial of service.

How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

I don't know


How can this vulnerability be detected on my network or system? Can you suggest some commands?

I don't know


What immediate steps should I take to mitigate this vulnerability?

I don't know


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart