6.7
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the kernel context. Such a flaw can lead to taking control over the entire system.
First identified on Nissan Leaf ZE1 manufactured in 2020.
First identified on Nissan Leaf ZE1 manufactured in 2020.
Basic Information
ID
CVE-2025-32060
Source
ASRG
Published
Feb 15, 2026 at 10:46
Affected Product
Vendor
Bosch
Product
Infotainment system ECU
Version
283C30861E
Affected Versions
Bosch Infotainment system ECU 283C30861E