PT-2026-32137 · Go · Github.Com/Teslamotors/Fleet-Telemetry

Published

2026-04-01

·

Updated

2026-04-01

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Summary

A vulnerability in vehicle authentication allows threat actor with valid client credentials (i.e., a private key and certificate from a rooted infotainment system) to impersonate arbitrary VINs when authenticating to the telemetry server.

Impact

The attacker would be able to submit falsified telemetry records for arbitrary VINs.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-PRXJ-3GCV-CQRH

Affected Products

Github.Com/Teslamotors/Fleet-Telemetry