Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Perception · Dominant path
Perception-to-action
Manipulated tire-pressure sensor messages enter the vehicle’s trusted perception channel and can influence the control module’s decisions.
Cross-domain authority chain
RF perception to remote code execution to CAN actuation bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Manipulated tire-pressure sensor messages enter the vehicle’s trusted perception channel and can influence the control module’s decisions.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception-to-action
Manipulated tire-pressure sensor messages enter the vehicle’s trusted perception channel and can influence the control module’s decisions.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Firmware-update fleet update.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Adjacent RF range to inject crafted TPMS cert_response.
- Execution complexity
EC 2 - Specialist multi-step technique
Reproducible integer-overflow exploit.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
The corrupted perception and control path leads to actuation (immobilizer and lock state) affecting vehicle security and theft risk, safety-margin reduction.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Manipulated tire-pressure sensor messages enter the vehicle’s trusted perception channel and can influence the control module’s decisions.
- Authority
AT 3 - Administrative or command authority
The module trusting TPMS perception is the security and immobilizer controller.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
RF perception to remote code execution to CAN actuation bridge.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Portable firmware exploit.
- Execution scale
SX 2 - Proximity-bound repetition
The TPMS exploit must be delivered within radio range of each target vehicle.
- Recovery burden
OR 4 - Fleet action or replacement
Firmware-update fleet update.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Manipulated tire-pressure sensor messages enter the vehicle’s trusted perception channel and can influence the control module’s decisions.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:3/DP:4/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLERead the scoring method →Safety · Supporting path
Device-control safety
CAN-level influence can disable protective functions or unlock the vehicle, reducing safety margins and enabling theft or interference with vehicle controls.
Proximity or local access
Adjacent RF and TPMS wireless range, no physical contact, without credentials.
EvidenceNVD
Cross-domain authority chain
Cross-domain authority transfer: RF sensor input to code execution on security module to CAN bus to vehicle commands, a reusable multi-hop bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Credible safety consequence
CAN-level influence can disable protective functions or unlock the vehicle, reducing safety margins and enabling theft or interference with vehicle controls.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
CAN-level influence can disable protective functions or unlock the vehicle, reducing safety margins and enabling theft or interference with vehicle controls.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Tesla remediation required a firmware update and coordinated rollout across affected vehicles.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Adjacent RF and TPMS wireless range, no physical contact, without credentials.
- Execution complexity
EC 2 - Specialist multi-step technique
The Pwn2Own demonstration used a repeatable but specialist integer-overflow exploit chain against the VCSEC module.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
CAN-level influence can disable protective functions or unlock the vehicle, reducing safety margins and enabling theft or interference with vehicle controls.
- Data / perception
DP 3 - Sensitive device or personal data
The path changes vehicle-security state without independently exposing a broader store of sensitive data.
- Authority
AT 3 - Administrative or command authority
Administrator and service authority over the VCSEC security module (immobilizer, locks) plus CAN-command injection, but not a signing and firmware-update trust root.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Cross-domain authority transfer: RF sensor input to code execution on security module to CAN bus to vehicle commands, a reusable multi-hop bridge.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The crafted TPMS input can be reused against vehicles that contain the same vulnerable VCSEC implementation.
- Execution scale
SX 2 - Proximity-bound repetition
Still per-vehicle proximity attack, no fleet-wide remote trigger.
- Recovery burden
OR 4 - Fleet action or replacement
Tesla remediation required a firmware update and coordinated rollout across affected vehicles.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. CAN-level influence can disable protective functions or unlock the vehicle, reducing safety margins and enabling theft or interference with vehicle controls.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the perception transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2025-2082
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082) at CRITICAL — the worst of 2 risk paths (perception, safety). The dominant consequence is manipulated perception that drives action.
Vulnerability
Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082). Reported attack vector: Adjacent network (wireless TPMS / RF range).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_TO_ACTION → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:3/DP:4/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability and complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.
- Distinct terminal: the TPMS sensor-trust/perception path is weaponized and drives physical action. RE:2 adjacent RF range to inject crafted TPMS cert_response. EC:2 reproducible integer-overflow exploit. AT:3 the module trusting TPMS perception is the security/immobilizer controller; gaining control of it subverts a safety-relevant sensor-trust boundary. PH:3 the corrupted perception/control path leads to actuation (immobilizer/lock state) affecting vehicle security and theft risk, safety-margin reduction. DP:4 a safety-relevant sensor/perception input (TPMS, a vehicle sensor-trust channel) is manipulated and feeds a control module.
- perception_feeds_action — true: manipulated TPMS perception is processed by VCSEC which actuates immobilizer/lock and bridges CAN. CH:4 RF perception -> RCE -> CAN actuation bridge. SR:4 portable firmware exploit. SX:2 per-vehicle proximity. OR:4 OTA fleet update. EV:3 reproduced at Pwn2Own. PATCH_AVAILABLE; no in-the-wild exploitation.
DEVICE_CONTROL_SAFETY → HIGH
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability and complexity-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.
RE:2 adjacent RF/TPMS wireless range, no physical contact, no creds. EC:2 advanced-but-reproducible memory-corruption integer overflow exploit chain, demonstrated working at Pwn2Own. AT:3 admin/service authority over the VCSEC security module (immobilizer, locks) plus CAN-command injection, but not a signing/OTA trust root. PH:3 safety-margin reduction / unsafe control influence via CAN (immobilizer disable, door unlock) enabling theft and potential interference with controls; demonstrated impacts are control-plane bypass rather than crash-level injury, so not PH:4. DP:3 firmware/security-relevant operational state of a control module. CH:4 cross-domain authority transfer: RF sensor input -> code exec on security module -> CAN bus -> vehicle commands, a reusable multi-hop bridge. SR:4 same firmware/hardware exploit is portable across identical units (shared firmware artifact). SX:2 still per-vehicle proximity attack, no fleet-wide remote trigger. OR:4 remediation required an OTA firmware update pushed across the affected fleet (fleet reprovision-class). EV:3 reproduced live at Pwn2Own Automotive 2024. PATCH_AVAILABLE; not known exploited in the wild.
Published baseline
- v3.0 7.5 HIGH —
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H— ZDI via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0018 (“Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082)”), paths.cfse.ai/CPATH-2026-0018 (published 2026-06-03).