Mercedes-Benz NTG6 Head Unit Arbitrary File Write Vulnerability

Vulnerability

A vulnerability allowing arbitrary file write has been identified in the Mercedes-Benz NTG6 head unit. This issue arises from functions that import or export profile settings via USB. The profile backup, when exported, is processed by a service that inadvertently drops a specified file. Due to insufficient validation, an attacker can manipulate the file path to write arbitrary content, leveraging the service's permissions.

Impact

Exploitation of this vulnerability allows for arbitrary file writing on the head unit, with the potential to execute the written file under the service's permissions.

Reproduction

The vulnerability can be reproduced by exporting a user profile backup to a USB drive. The 'vt_ab.ud2' file, when decoded, is processed by the head unit's text-to-speech service. This file can be manipulated to include a payload that, when the backup is imported, triggers the arbitrary file write by directing the service to drop a file at a specified path.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.5
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.