CVE-2025-32058Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the infotainment main SoC to perform code execution on the RH850 module and subsequently send arbitrary CAN messages over the connected CAN bus. First identified on Nissan Leaf ZE1 manufactured in 2020.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-15); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-02-15: 3Mentions · 2026-02-17: 3Mentions · 2026-02-20: 1Technical Details · 2026-02-15: 2Technical Details · 2026-02-17: 2Technical Details · 2026-02-20: 102-1502-1702-20
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-153
Disclosure3
2026-02-173
Disclosure2General1
2026-02-201
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-32058 (CVSS:9.3, CRITICAL) is Awaiting Analysis. The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment..https://nvd.nist.gov/vuln/detail/CVE-2025-32058 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-32058, a critical vulnerability affecting Bosch infotainment ECUs that use RH850 modules, is currently awaiting analysis; no Proof of Concept, exploit, patch information, or evidence of active exploitation is available.

    1000030
    171 followersView on X
  • transilienceai@transilienceai
    General

    @TheHackerWire Note: Some sources mention a related Bluetooth stack overflow in the same ECU (Alps Alpine-developed), but CVE-2025-32058 specifically targets the RH850 INC protocol handling. #Bluetooth #CVE

    Post summary

    A brief tweet notes that CVE‑2025‑32058 affects RH850 INC protocol handling, with a mention of a related Bluetooth stack overflow, but provides no PoC, exploit, or patch details.

    1000042
    313 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @TheHackerWire CVE-2025-32058 is a critical stack-based buffer overflow vulnerability (CWE-121) in the Bosch Infotainment ECU, specifically in the RH850 module handling CAN communication via a custom INC protocol interface. ⚠️ #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE-2025-32058 as a critical stack-based buffer overflow in the Bosch Infotainment ECU’s RH850 module, providing specific technical details about the vulnerability.

    1000055
    313 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-32058 - Critical The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulne... https://www.thehackerwire.com/vulnerability/CVE-2025-32058/ https://t.co/OakO52djLZ

    Post summary

    The tweet announces the discovery of CVE‑2025‑32058 in a Bosch Infotainment ECU, noting a potential critical flaw in the RH850 CAN module, but offers no further exploitation or mitigation details.

    1000060
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-32058 The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom proto… https://www.cve.org/CVERecord?id=CVE-2025-32058

    Post summary

    The passage merely references CVE‑2025‑32058 and provides minimal contextual details about the affected Bosch Infotainment ECU, without any PoC, exploit, or mitigation information.

    00010405
    56.4K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-32058: Stack Overflow in processing req... Stack overflow in Bosch's RH850-based ECU creates pivot from infotainment to CAN bus, enabling full vehicle control fro... https://zerodaysignal.com/vulnerability/CVE-2025-32058 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A stack overflow vulnerability in Bosch's RH850-based ECU could let an attacker pivot from the infotainment system to the CAN bus, potentially taking full control of the vehicle.

    0000053
    131 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-32058 Code Execution Vulnerability in Bosch Infotainment ECU RH850 CAN Communication Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-32058

    Post summary

    A code execution vulnerability (CVE-2025-32058) affecting the Bosch Infotainment ECU RH850 CAN Communication Module has been disclosed.

    0000037
    4.0K followersView on X

Explore more