CRITICAL🇵🇱 Wersja polska

CVE-2024-46442

CVSS 9.8v3.1pub. 2024-12-10upd. 2026-07-05

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

🤖 AI Analysis
How it works

The vulnerability (CWE-307) consists of the lack of a mechanism to limit excessive authentication attempts (no account lockout, CAPTCHA, request limit, or similar protections). An attacker can repeatedly send login requests, systematically testing combinations of credentials until gaining access. Since the attack requires no user interaction or prior privileges, it can be carried out entirely remotely.

Impact

Successful execution of the attack gives the attacker full access to the BYD vehicle's headunit system, which may result in breach of confidentiality, integrity, and availability of system data and functions — including potentially vehicle-related functions.

Mitigation & patch

Apply patches available from the manufacturer according to references (byd.com, bydauto.com.cn). Until an update is applied, it is recommended to isolate the system from untrusted networks and monitor login attempts. Vulnerability details are available in the repository: https://github.com/zgsnj123/BYD_headunit_vuls/tree/main

Who is affected

BYD Dilink Headunit System in versions v3.0 to v4.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References