{"api_version":"1","generated_at":"2026-07-24T18:56:29+00:00","cve":"CVE-2022-23126","urls":{"html":"https://cve.report/CVE-2022-23126","api":"https://cve.report/api/cve/CVE-2022-23126.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-23126","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-23126"},"summary":{"title":"CVE-2022-23126","description":"TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-01-24 19:15:00","updated_at":"2023-11-07 03:44:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://github.com/adriankumpf/teslamate/releases/tag/v1.25.1","name":"https://github.com/adriankumpf/teslamate/releases/tag/v1.25.1","refsource":"CONFIRM","tags":[],"title":"Release v1.25.1 · adriankumpf/teslamate · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/teslascope/status/1481252837174624258","name":"https://twitter.com/teslascope/status/1481252837174624258","refsource":"MISC","tags":[],"title":"Teslascope on Twitter: \"Just to chime in, any vehicles on TezLab were not at any risk of \"full remote control\" and as such, vehicles whether on TezLab or other services were not related to this. ????\n\nDavid's thread pertains to a vulnerability in Teslamate, now patched. https://t.co/bv3EH5uDmI… https://t.co/9mEm3lPlnQ\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/@david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028","name":"https://medium.com/@david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028","refsource":"MISC","tags":[],"title":"How I got access to 25+ Tesla’s around the world. By accident. And curiosity. | by David Colombo | Jan, 2022 | Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/%40david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028","name":"https://medium.com/%40david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028","refsource":"","tags":[],"title":"How I got access to 25+ Tesla’s around the world. By accident. And curiosity. | by David Colombo | Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/adriankumpf/teslamate/compare/v1.25.0...v1.25.1","name":"https://github.com/adriankumpf/teslamate/compare/v1.25.0...v1.25.1","refsource":"MISC","tags":[],"title":"Comparing v1.25.0...v1.25.1 · adriankumpf/teslamate · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/adriankumpf/teslamate/commit/fff6915e7364f83b3030f980d5743299c4e5260d","name":"https://github.com/adriankumpf/teslamate/commit/fff6915e7364f83b3030f980d5743299c4e5260d","refsource":"MISC","tags":[],"title":"Disable anonymous login to Grafana · adriankumpf/teslamate@fff6915 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-23126","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23126","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"23126","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"teslamate_project","cpe5":"teslamate","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-23126","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://github.com/adriankumpf/teslamate/commit/fff6915e7364f83b3030f980d5743299c4e5260d","url":"https://github.com/adriankumpf/teslamate/commit/fff6915e7364f83b3030f980d5743299c4e5260d"},{"refsource":"MISC","name":"https://twitter.com/teslascope/status/1481252837174624258","url":"https://twitter.com/teslascope/status/1481252837174624258"},{"refsource":"MISC","name":"https://github.com/adriankumpf/teslamate/compare/v1.25.0...v1.25.1","url":"https://github.com/adriankumpf/teslamate/compare/v1.25.0...v1.25.1"},{"refsource":"CONFIRM","name":"https://github.com/adriankumpf/teslamate/releases/tag/v1.25.1","url":"https://github.com/adriankumpf/teslamate/releases/tag/v1.25.1"},{"refsource":"MISC","name":"https://medium.com/@david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028","url":"https://medium.com/@david_colombo/how-i-got-access-to-25-teslas-around-the-world-by-accident-and-curiosity-8b9ef040a028"}]}},"nvd":{"publishedDate":"2022-01-24 19:15:00","lastModifiedDate":"2023-11-07 03:44:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:teslamate_project:teslamate:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"23126","Ordinal":"225737","Title":"CVE-2022-23126","CVE":"CVE-2022-23126","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"23126","Ordinal":"1","NoteData":"TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.","Type":"Description","Title":null},{"CveYear":"2022","CveId":"23126","Ordinal":"2","NoteData":"2022-01-24","Type":"Other","Title":"Published"},{"CveYear":"2022","CveId":"23126","Ordinal":"3","NoteData":"2022-01-24","Type":"Other","Title":"Modified"}]}}}