Carlinkit manufactures automotive integration devices and dongles such as the AutoKit and CPC200 series that bridge smartphone operating systems to vehicle infotainment systems. The recurring vulnerability patterns center on cryptographic-verification weaknesses, hard-coded credentials, and lack of immutable root-of-trust protections in the hardware, reflecting the firmware-update and authentication demands of embedded automotive connectivity products; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carlinkit over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2765HIGH CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on | Apr 23, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-2764HIGH CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi | Apr 23, 2025 | 8.0 | 22 | NO | NO |
CVE-2025-2762HIGH CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of | Apr 23, 2025 | 7.8 | 22 | NO | NO |
CVE-2025-2763MEDIUM CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary cod | Apr 23, 2025 | 6.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carlinkit.
Media articles that mention a CVE ID that affects a product developed by Carlinkit — matched by CVE ID, not by vendor name.