← Registry

CPATH-2026-0018 · DRONE AV

Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence PERCEPTION_TO_ACTION perception · Evidence EV:3 (reproduced / report-backed) · Liveness PATCH_AVAILABLE
CPATH IDCPATH-2026-0018
CVE(s)CVE-2025-2082
Device / classTesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082) (DRONE AV)
VendorTesla
Dominant consequencePERCEPTION_TO_ACTION (perception)
Paths verdictCRITICAL (worst of 2 paths)
Published baseline
v3.0 7.5 HIGH CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · ZDI via NVD
Baseline relationship▼ Paths higher
Consequence dimension(s)#1 #2 #8 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

perception

PERCEPTION_TO_ACTION

CRITICAL
Reachability RE:2
Complexity EC:2
Consequence PERCEPTION_TO_ACTION
Scale SR:4 / SX:2
Verdict CRITICAL
Reachability 2
Complexity 2
Exposure 2
Physical / safety 3
Data / perception 4
Authority 3
Chainability 4
Reuse scale 4
Execution scale 2
Recovery 4
Evidence EV:3 · reproduced / report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:3/DP:4/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLE

Physical/safety

DEVICE_CONTROL_SAFETY

HIGH
Reachability RE:2
Complexity EC:2
Consequence DEVICE_CONTROL_SAFETY
Scale SR:4 / SX:2
Verdict HIGH
Reachability 2
Complexity 2
Exposure 2
Physical / safety 3
Data / perception 3
Authority 3
Chainability 4
Reuse scale 4
Execution scale 2
Recovery 4
Evidence EV:3 · reproduced / report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLE

Assessment

CFSE Consequence Paths assesses Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082) at CRITICAL — the worst of 2 risk paths (perception, safety). The dominant consequence is manipulated perception that drives action.

Vulnerability

Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082). Reported attack vector: Adjacent network (wireless TPMS / RF range).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:3/DP:4/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability and complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:3/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability and complexity-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.

RE:2 adjacent RF/TPMS wireless range, no physical contact, no creds. EC:2 advanced-but-reproducible memory-corruption integer overflow exploit chain, demonstrated working at Pwn2Own. AT:3 admin/service authority over the VCSEC security module (immobilizer, locks) plus CAN-command injection, but not a signing/OTA trust root. PH:3 safety-margin reduction / unsafe control influence via CAN (immobilizer disable, door unlock) enabling theft and potential interference with controls; demonstrated impacts are control-plane bypass rather than crash-level injury, so not PH:4. DP:3 firmware/security-relevant operational state of a control module. CH:4 cross-domain authority transfer: RF sensor input -> code exec on security module -> CAN bus -> vehicle commands, a reusable multi-hop bridge. SR:4 same firmware/hardware exploit is portable across identical units (shared firmware artifact). SX:2 still per-vehicle proximity attack, no fleet-wide remote trigger. OR:4 remediation required an OTA firmware update pushed across the affected fleet (fleet reprovision-class). EV:3 reproduced live at Pwn2Own Automotive 2024. PATCH_AVAILABLE; not known exploited in the wild.

Published baseline

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0018 (“Tesla Model 3 VCSEC TPMS Integer Overflow RCE (CVE-2025-2082)”), paths.cfse.ai/CPATH-2026-0018 (published 2026-06-03).