---
id: CVE-2025-34251
title: >-
  Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an
  authentication bypass vulnerability
summary: >-
  Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an
  authentication bypass vulnerability. The TCU runs the Android Debug Bridge
  (adbd) as root and, despite a “lockdown” check that disables adb shell, still
  permits a…
severity: none
cwe:
  - CWE-269
  - CWE-288
published: '2025-10-07'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34251'
references:
  - url: >-
      https://www.nccgroup.com/research-blog/technical-advisory-tesla-telematics-control-unit-adb-auth-bypass/
    label: disclosure@vulncheck.com
  - url: 'https://www.tesla.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/tesla-tcu-auth-bypass'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00446
epssPercentile: 0.36803
ingestedAt: '2026-10-09T12:53:28.927Z'
---

## Overview

Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, despite a “lockdown” check that disables adb shell, still permits adb push/pull and adb forward. Because adbd is privileged and the device’s USB port is exposed externally, an attacker with physical access can write an arbitrary file to a writable location and then overwrite the kernel’s uevent_helper or /proc/sys/kernel/hotplug entries via ADB, causing the script to be executed with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
