PT-2022-15870 · Teslamate+1 · Teslamate+1

Published

2022-01-24

·

Updated

2025-05-28

·

CVE-2022-23126

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TeslaMate versions prior to 1.25.1
Description The issue allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.
Recommendations For TeslaMate versions prior to 1.25.1, update to version 1.25.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Grafana login to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-23126

Affected Products

Grafana
Teslamate