Teslamate is a vehicle-tracking and telemetry logging application that aggregates Tesla vehicle data and operational history. The recurring weakness classes in its vulnerability profile center on improper authentication and exposure of sensitive information, reflecting the application's role handling vehicle location, operational state, and owner data.
The number and severity of CVEs published that impact products developed by Teslamate over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23126CRITICAL TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation | Jan 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-31634CRITICAL In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an a | Mar 27, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-29857MEDIUM An issue in Teslamate v1.27.1 allows attackers to obtain sensitive information via directly accessing the teslamate link. | May 18, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teslamate.
Media articles that mention a CVE ID that affects a product developed by Teslamate — matched by CVE ID, not by vendor name.