Audi's vulnerability profile centers on a narrow scope of automotive infotainment and traffic management systems, including the Universal Traffic Recorder product line and multimedia interfaces such as the MMI platform. Vulnerabilities affecting these products skew toward serious outcomes and recur through access-control and authentication weaknesses, input-validation flaws including cross-site scripting, buffer overflows, and unsafe file-handling that reflect the embedded and web-facing nature of automotive software. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Audi over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-45583CRITICAL Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and | Sep 12, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-45584HIGH Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download car information without authentication. | Sep 12, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-45587HIGH A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Sep 12, 2025 | 7.0 | 24 | NO | NO |
CVE-2020-27524HIGH On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may | Nov 11, 2020 | 7.1 | 23 | NO | NO |
CVE-2025-45586HIGH An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a crafted PUT request. | Sep 12, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-45585MEDIUM Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a | Sep 12, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Audi.
Media articles that mention a CVE ID that affects a product developed by Audi — matched by CVE ID, not by vendor name.