Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2020-10558 — Tesla Hack All Vehicles DoS Infotainment Touchscreen Interface CVE-2020-10558 | Kitploit
工具/GitHubGitHub/nullze/cve-2020-10558
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPapers & ResearchLearning & Education
GitHubnullze/cve-2020-10558

CVE-2020-10558

Tesla Hack All Vehicles DoS Infotainment Touchscreen Interface CVE-2020-10558

查看仓库
1525个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

CVE-2020-10558:特斯拉 Model S/3/X 拒绝服务 (DoS)

安全研究员: Jacob Archuleta (@nullze)

📝 漏洞概述

在特斯拉 Model 3、Model S 和 Model X(所有早于 2020.4.10 的版本)中发现了一个严重的拒绝服务 (DoS) 漏洞。该漏洞允许远程攻击者通过精心构造的网页使基于 Chromium 的信息娱乐系统 (MCU) 崩溃,导致关键车辆功能丧失,包括:

  • 速度表显示
  • 气候控制
  • Autopilot 可视化和警报
  • 转向信号音视频反馈

🛠️ 技术分析

该漏洞源于车辆内置浏览器对特定 Web 指令处理不当。利用资源耗尽或进程终止向量,攻击者可以强制 Model3-Icefish(或等效 MCU)进程进入无响应状态。

攻击向量

  1. 初始访问: 受害者通过特斯拉车载浏览器导航至恶意 URL。
  2. 载荷执行: 精心构造的 HTML/JavaScript 触发内核级进程崩溃。
  3. 影响: CID(中央信息显示屏)黑屏或冻结,有效禁用驾驶员对车辆次级系统的界面。

🛡️ 修复与披露

我通过 特斯拉 Bugcrowd 漏洞赏金计划遵循了负责任的披露流程。特斯拉验证了该发现,并发布了全车队的 OTA(空中升级)更新(v2020.4.10)以缓解此问题。

  • NVD 链接: CVE-2020-10558
  • 状态: 已解决 / 已修复
  • 荣誉: 被列入 特斯拉安全研究名人堂。

免责声明:此仓库仅用于教育和历史记录目的。本人致力于汽车生态系统的安全与保障。

详细分析可见:https://cylect.io/blog/Tesla_Model_3_Vuln/

媒体报道:

https://cyber.vumetric.com/vulns/tesla/risk/high/

https://news.ycombinator.com/item?id=22641197

https://portswigger.net/daily-swig/web-based-attack-crashes-tesla-driver-interface

https://securityboulevard.com/2020/08/tesla-model-3-vulnerability-what-you-need-to-know-about-the-web-browser-bug/

https://dimov.pro/tesla-model-3-vulnerability-what-you-need-to-know-about-the-web-browser-bug/

https://www.securityweek.com/vulnerability-exposed-tesla-central-touchscreen-dos-attacks/

https://gridinsoft.com/blogs/is-researcher-found-that-the-tesla-model-3-interface-is-vulnerable-to-dos-attacks/

https://eurocybcar.com/enhttps:/eurocybcar.com/casos_crackeos/researcher-hacks-into-a-teslas-screen/

https://neomotor.epe.es/actualidad/tesla-model-3-este-es-el-problema-que-encontro-un-hacker-en-su-pantalla-DFNM4104

https://hackercar.com/que-descubrio-un-hacker-en-la-pantalla-de-este-tesla/

https://bugcrowd.com/nullze

https://sploitus.com/exploit?id=C087F7C1-D3CA-5595-B8C8-B1545B0F8B61

https://vulners.com/cve/CVE-2020-10558

https://www.cybersecurity-help.cz/vdb/SB2020032310

https://www.cisa.gov/news-events/bulletins/sb20-090-0

https://www.flu-project.com/2020/04/cve-2020-10558-en-tesla-model-3-Denegacion-servicio-completa-pantalla.html

https://www.secquest.co.uk/white-papers/exploring-common-vulnerabilities-in-self-driving-cars

https://labs.northit.co.uk/cve/2020/10558/

https://www.genians.com/platform/Tesla_Model_S_Car/?id=29144

学术文献:

https://www.mdpi.com/2078-2489/15/1/14

下载工具