Hyundai's vulnerability profile centers on in-vehicle infotainment systems and associated connectivity services such as Blue Link, representing the automotive sector's expanding attack surface as vehicles integrate networked and remote-management capabilities. The recurring weakness classes—privilege management, authorization flaws, authentication bypass, and path traversal—reflect the challenges of securing embedded systems with legacy constraints and wireless connectivity requirements. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hyundai over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55618HIGH In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered. | Aug 27, 2025 | 7.3 | 25 | NO | NO |
CVE-2017-6054HIGH A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sens | Apr 26, 2017 | 7.5 | 25 | NO | NO |
CVE-2023-26246HIGH An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware install | Apr 27, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-26245HIGH An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware install | Apr 27, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-26243HIGH An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an informati | Apr 27, 2023 | 7.8 | 23 | NO | NO |
CVE-2022-37418MEDIUM The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform unlock operations and force a resynchroni | Aug 24, 2022 | 6.4 | 22 | NO | NO |
CVE-2023-26244HIGH An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is used during the firmware instal | Apr 27, 2023 | 7.8 | 20 | NO | NO |
A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verified, which may allow a remote attacker to | Apr 26, 2017 | 3.7 | 18 | NO | NO |
CVE-2023-39373MEDIUM
A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay.
| Sep 3, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hyundai.
Media articles that mention a CVE ID that affects a product developed by Hyundai — matched by CVE ID, not by vendor name.