CVE-2019-12797: Elmelectronics ELM27 Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.

Affected products

Published 2019-07-31. Last modified 2026-06-17.