Multiple vulnerabilities in the Mazda Connect infotainment system could allow attackers to execute arbitrary code with root access.
The vulnerabilities are caused by improper input sanitization in the Mazda Connect CMU, allowing attackers with physical access to exploit the system using a crafted USB device.
The vulnerabilities impact the Mazda Connect CMU system installed in Mazda 3 models from 2014 to 2021.
The vulnerabilities could result in arbitrary code execution, command injections, and unauthorized firmware uploads, potentially affecting vehicle functions and safety.