{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-16T07:42:14.294","vulnerabilities":[{"cve":{"id":"CVE-2024-6032","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2025-04-30T20:15:21.283","lastModified":"2025-08-12T15:11:45.130","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on the target system in order to exploit this vulnerability.\n \nThe specific flaw exists within the ql_atfwd process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code on the target modem in the context of root. Was ZDI-CAN-23201."},{"lang":"es","value":"Vulnerabilidad de ejecución de código por inyección de comandos ql_atfwd en el módem Iris del Tesla Model S. Esta vulnerabilidad permite a atacantes locales ejecutar código arbitrario en los vehículos Tesla Model S afectados. Para explotar esta vulnerabilidad, un atacante debe obtener primero la capacidad de ejecutar código en el sistema objetivo. La falla específica se encuentra en el proceso ql_atfwd. El problema se debe a la falta de validación adecuada de una cadena proporcionada por el usuario antes de usarla para ejecutar una llamada al sistema. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el módem objetivo con acceso root. Era ZDI-CAN-23201."}],"metrics":{"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tesla:model_s_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2024.8","matchCriteriaId":"D1F9CBB6-013F-43C4-B01D-D8CBE1623F4E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tesla:model_s:-:*:*:*:*:*:*:*","matchCriteriaId":"8D28E699-B843-4641-9BA6-406D88231E7C"}]}]}],"references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-264/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]}]}}]}