Kaspersky: Security flaws threatening car safety
Source: Promo
Thursday, 30.10.2025.
14:34
Thursday, 30.10.2025.
14:34
(Photo: Shutterstock/Zapp2Photo)
By exploiting a zero-day vulnerability in a publicly available application of a subcontractor, it was possible to take control of the vehicle’s telematics system, thereby jeopardizing the physical safety of the driver and passengers.
For example, attackers could force gear changes or turn off the engine while the vehicle is in motion.
The findings highlight potential weaknesses in the automotive industry’s cybersecurity and are a call for the introduction of stricter security measures.
Automaker’s side
The security audit was conducted remotely and focused on the manufacturer’s publicly available services and subcontractor infrastructure.
Kaspersky identified several exposed web services.
First, by exploiting a zero-day SQL injection vulnerability in a wiki application (a web platform that allows users to collaboratively create, edit, and manage content), the researchers were able to extract a list of users on the subcontractor side with hashed passwords, some of which were affected due to weak password policies.
This intrusion provided access to the issue tracking system - a software tool used to manage and track tasks, bugs, or problems within a project.
This system contained sensitive configuration data about the manufacturer’s telematics infrastructure, including a file with hashed passwords of users of one of the vehicle telematics servers.
In a modern car, telematics allows the collection, transmission, analysis, and use of various data (e.g., speed, geolocation, etc.) from connected vehicles.
Connected vehicle side
(Photo: Unsplash/Remy Lovesy)
On the connected vehicle side, Kaspersky discovered a misconfigured firewall that exposed internal servers.
Using the previously obtained password for the service account, the researchers accessed the server’s file system and discovered the credentials of another subcontractor, which gave them complete control over the telematics infrastructure.
Most alarmingly, the researchers discovered a firmware update command that allowed them to upload modified firmware to the Telematics Control Unit (TCU).
This gave them access to the CAN (Controller Area Network) bus - a system that connects various parts of the vehicle, such as the engine and sensors.
Subsequently, various other systems were also accessed, including the engine, transmission, etc. This allowed for the potential manipulation of a whole range of critical vehicle functions, which could jeopardize the safety of the driver and passengers.
– The security flaws stem from issues that are quite common in the automotive industry: publicly available web services, weak passwords, lack of multi-factor authentication (2FA), and unencrypted storage of sensitive data.
This incident shows how one weak link in the subcontractor’s infrastructure can lead to the complete compromise of all connected vehicles.
The automotive industry must prioritize strong cybersecurity practices, especially when it comes to third-party systems, to protect drivers and maintain trust in connected vehicle technologies, comments Artem Zinenko, Head of Kaspersky ICS CERT Vulnerability Research and Assessment Team.
Kaspersky recommends that subcontractors restrict access to web services via VPN, isolate services from corporate networks, enforce strict password policies, implement 2FA, encrypt sensitive data, and integrate the logging system with a SIEM system for real-time monitoring.
For the automaker, Kaspersky advises restricting access to the telematics platform from the vehicle network segment, using allowlist access for network interactions, disabling SSH password authentication, running services with least privileges, and ensuring authentication of commands in TCUs, along with SIEM system integration.
Companies:
Kaspersky
Tags:
Kaspersky
Security Analyst Summit 2025
Artem Zinenko
zero day SQL injection
issue tracking system
security
vehicles
hashed passwords
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora