CVE 9.3 CRITICAL

Stack Overflow in processing requests over INC interface on RH850 side of Infotainment ECU_CVE-2025-32058

9.3 / 10
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the infotainment main SoC to perform code execution on the RH850 module and subsequently send arbitrary CAN messages over the connected CAN bus.



First identified on Nissan Leaf ZE1 manufactured in 2020.

AI Analysis

Stack overflow vulnerability in the RH850 module of the Infotainment ECU, allowing code execution and arbitrary CAN message sending

Basic Information

ID CVE-2025-32058
Source ASRG
Published Feb 15, 2026 at 10:44

Affected Product

Vendor Bosch
Product Infotainment system ECU
Version 283C30861E
Affected Versions Bosch Infotainment system ECU 283C30861E

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Bosch
Product Infotainment system ECU
Version 283C30861E

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.