The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not verified. As a result, an attacker may be able to impersonate a Redbend backend server using a self-signed certificate.



First identified on Nissan Leaf ZE1 manufactured in 2020.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 24 Jan 2026 01:45:00 +0900

Type Values Removed Values Added
First Time appeared Bosch
Bosch infotainment System Ecu
Vendors & Products Bosch
Bosch infotainment System Ecu

Fri, 23 Jan 2026 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 00:45:00 +0900

Type Values Removed Values Added
Description The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not verified. As a result, an attacker may be able to impersonate a Redbend backend server using a self-signed certificate. First identified on Nissan Leaf ZE1 manufactured in 2020.
Title Misconfigured SSL/TLS communication of Redbend service for Infotainment ECU
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ASRG

Published:

Updated: 2026-01-22T15:43:11.681Z

Reserved: 2025-04-03T15:32:43.281Z

Link: CVE-2025-32057

cve-icon Vulnrichment

Updated: 2026-01-22T15:43:03.410Z

cve-icon NVD

Status : Received

Published: 2026-01-22T16:16:06.890

Modified: 2026-01-22T16:16:06.890

Link: CVE-2025-32057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-24T01:32:27Z

Weaknesses