VendorsMercedes-Benzheadunit_ntg6_mercedes-benz_user_experience2021
Vulnerabilities

Mercedes-Benz Headunit NTG6 Mercedes-Benz User Experience (MBUX) 2021

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-23907
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The count in MultiSvGet, GetAttributes, and MultiSvSet is not checked in the HiQnet Protocol, leading to remote code execution.
Published 2021-05-13 · Modified
9.8EPSS 0.024
CVE-2021-23908
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.
Published 2021-05-13 · Modified
9.8EPSS 0.024
CVE-2023-34404
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all registered services in router and achieve command injection vulnerability.
Published 2025-02-13 · Analyzed
4.9EPSS 0.004
CVE-2024-37603
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.
Published 2025-02-13 · Analyzed
4.6EPSS 0.003