mediumCVSS 5.9Vulnerability

GHSA-prxj-3gcv-cqrh

### Summary A vulnerability in vehicle authentication allows threat actor with valid client credentials (i.e., a private key and certificate from a rooted infotainment system) to impersonate arbitrary VINs when authenticating to the telemetry server. ### Impact The attacker would be able to submit falsified telemetry records for arbitrary VINs.

Properties

ghsa_id
GHSA-prxj-3gcv-cqrh
severity
medium
summary
Tesla Fleet Telemetry allows spoofing telemetry for arbitrary vehicles via compromised vehicle credentials
cvss_score
5.9
cve_id
GHSA-prxj-3gcv-cqrh
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-04-01T23:01:38Z
source_url
https://github.com/advisories/GHSA-prxj-3gcv-cqrh
ghsa_updated
2026-04-01T23:01:39Z

Related Entities (3)

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]go/github.com/teslamotors/fleet-telemetry

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

Explore deeper with Ninja Signal's threat intelligence graph