CVE-2025-32057 Details
Description
The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not verified. As a result, an attacker may be able to impersonate a Redbend backend server using a self-signed certificate. First identified on Nissan Leaf ZE1 manufactured in 2020.
A vulnerability exists in the Bosch-manufactured infotainment ECU of the 2020 Nissan Leaf ZE1, related to the Redbend service used for over-the-air updates. The issue arises because the default SSL configuration does not properly verify server certificates, allowing an attacker to impersonate a Redbend server with a self-signed certificate. This could enable unauthorized access to the vehicle's update system and potentially exploit other vulnerabilities within the ECU.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 22, 2026CISA-ADP
Assessed Jan 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://i.blackhat.com/Asia-25/Asia-25-Evdokimov-Remote-Exploitation-of-Nissan-Leaf.pdf | [email protected] | BundleExploitTechnical Analysis |
| https://pcacybersecurity.com/resources/advisory/vulnerabilities-in-nissan-infotainment-manufactured-by-bosch | [email protected] | AdvisoryBundleRemedy |
| https://www.nissan.co.uk/vehicles/new-vehicles/leaf.html | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bosch Infotainment ECU | 283C30861E |
CPE
Remediation
| |
| Nissan Leaf ZE1 | 283C30861E |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | New CVE Received | [email protected] |
Volerion