IoT Security

Details Disclosed for Mercedes-Benz Infotainment Vulnerabilities

Kaspersky has disclosed the details of over a dozen vulnerabilities discovered in a Mercedes-Benz MBUX infotainment system. 

Car hacking

Kaspersky has disclosed the details of over a dozen vulnerabilities discovered in a Mercedes-Benz infotainment system, but the carmaker has assured customers that the security holes have been patched and they are not easy to exploit.

Kaspersky’s research of the Mercedes-Benz head unit, called Mercedes-Benz User Experience (MBUX), built on previous research conducted by a Chinese team that disclosed its findings in 2021. 

The Russian cybersecurity firm published a blog post describing its findings on Friday, when it also started releasing advisories for each of the identified vulnerabilities. The research targeted the first generation MBUX.

Several of the flaws can be exploited for DoS attacks, while others can be leveraged to obtain data, for command injection, and to escalate privileges. 

According to Kaspersky, it has demonstrated that an attacker who has physical access to the targeted vehicle can exploit some of the vulnerabilities to disable anti-theft protections in the head unit, perform tuning on the vehicle, and unlock paid services. The attacks were conducted using USB or custom UPC connections.

The vulnerabilities have been assigned 2023 and 2024 CVE identifiers, but Mercedes-Benz told SecurityWeek that it has been aware of Kaspersky’s findings since 2022. 

Advertisement. Scroll to continue reading.

“In August 2022, a team of external security researchers contacted us regarding the first generation MBUX – Mercedes-Benz User Experience,” a Mercedes-Benz spokesperson said in an emailed statement. 

“The topic described by the researchers requires physical access to the vehicle on site as well as access to the interior of the vehicle. In addition, the head unit has to be removed and opened. Newer versions of the infotainment system are not affected,” the spokesperson added.

Mercedes-Benz says the security of its products and services has ‘high priority’ and urged researchers to report findings through its vulnerability disclosure program. 

In the past, researchers disclosed vulnerabilities which they claimed could be exploited to remotely hack Mercedes-Benz cars

Other past cybersecurity findings impacted the carmaker’s IT infrastructure. One year ago, researchers reported that a GitHub token leaked by a Mercedes-Benz employee provided access to all the source code stored on the company’s GitHub Enterprise server.

Related: Unpatched Vulnerabilities Allow Hacking of Mazda Cars

Related: Mercedes-Benz USA Says Vendor Exposed Customer Information

Related: Millions of Kia Cars Were Vulnerable to Remote Hacking

Related Content

Data Breaches

The hackers stole internal IDs, names, email addresses, and business partner IDs from an internal management system.

IoT Security

Using low-cost receivers deployed along roads, academic researchers tracked drivers and their movement patterns.

Data Breaches

LKQ said the personal information of thousands of individuals was compromised as a result of the hacker attack.

IoT Security

Set for January 2026 at Automotive World in Tokyo, the contest will have six categories, including Tesla, infotainment systems, EV chargers, and automotive OSes.

IoT Security

Oligo Security has shared details on an Apple CarPlay attack that hackers may be able to launch without any interaction.

Vulnerabilities

A researcher has demonstrated how a platform used by over 1,000 dealerships in the US could have been used to hack cars.

IoT Security

Researchers showed how flaws in a bus’ onboard and remote systems can be exploited by hackers for tracking, control and spying. 

IoT Security

PCA Cyber Security has discovered critical vulnerabilities in the BlueSDK Bluetooth stack that could have allowed remote code execution on car systems.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version