CVE-2023-3028 describes critical authentication and encryption vulnerabilities in the HopeChart HQT-401 telematics unit's MQTT backend, potentially affecting other models as well. An unauthenticated attacker can access and manipulate sensitive vehicle telemetry data (e.g., GPS, speed, fuel) due to public MQTT topics and lack of message authentication/encryption. This allows for data impersonation, injection of malicious CAN bus commands, and full compromise of vehicle data. Rated 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the vulnerability is easily exploitable over the network with no user interaction. While no active exploitation or public exploit code is currently reported, the severe impact and ease of exploitation warrant immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
201808021036CPE matchmatch criteria | cpe:2.3:o:hopechart:hqt401_firmware:201808021036:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.