A security vulnerability in Tesla's Telematics Control Unit (TCU) allowed attackers with physical access to bypass security measures and allow full root-level code execution.
See also: Tesla protests new EPA policy
The issue arose from the incomplete securing of the Android Debug Bridge (ADB) on an external Micro USB port, allowing a physically present attacker to compromise the vehicle's TCU. Tesla has already fixed the vulnerability via an over-the-air (OTA) software update.

According to NCC Group, the vulnerability was present in software version v12 (2025.2.6) . Although the company had implemented logic to block direct shell access via adb shell on production devices, researchers found that this security was insufficient.
It failed to prevent two critical ADB functions: the ability to read and write files as root, using the adb pull and adb push, and the ability to forward network traffic with adb forward.
Since the ADB (adbd) process on the TCU runs with root privileges, these omissions created a strong attack surface.
An attacker could exploit this vulnerability by physically connecting a device to the TCU's Micro USB port. The attack involved several steps:
See also: Tesla drops 22% in Europe

1. **Payload Upload**: The attacker would use the adb push command to upload a malicious executable script to a TCU writable directory, such as /tmp.
2. **Initial Execution**: The attacker would exploit the uevent_helper . By writing the path of the malicious script to the uevent_helper file, he could trick the kernel into executing it with root privileges when a system event was triggered.
3. **Gaining Access**: A simple action such as reading a file with adb pull was enough to trigger a uevent, causing the malicious script to execute. In the proof of concept, the script started a Telnet server, to which the attacker could connect using a port forwarded via adb forward, granting them a root shell on the device.
The impact of this vulnerability is severe, as gaining root access to the TCU gives the attacker complete control over this component. Although the attack requires physical access, a compromised TCU could potentially serve as a launching point for further attacks on the vehicle's internal network.
The vulnerability was responsibly reported to Tesla on March 3, 2025. Tesla acknowledged the report the next day and began releasing an update to software version 2025.14 on April 24, 2025.
See also: Volvo Group: Data breach following Ransomware attack

The fix resolves the issue by completely disabling the ADB interface on the Micro USB port for production vehicles, ensuring that it can no longer be used as an attack point.
