CVE-2025-32063: Bosch Infotainment System Ecu
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server. First identified on Nissan Leaf ZE1 manufactured in 2020.
Affected products
- Bosch Infotainment System Ecu: version 283C30861E only
Published 2026-02-15. Last modified 2026-06-17.