Mercedes-Benz NTG 6 Head Unit Integer Overflow Vulnerability in User Data Import/Export Function

Vulnerability

An integer overflow vulnerability has been identified in the user data import/export function of Mercedes-Benz NTG 6 head units. This vulnerability requires local access to the vehicle's USB interface. An attacker can exploit this issue by sending prepared data, causing the User-Data service to fail. Although the service instance will automatically restart, the failure can disrupt normal functionality.

Impact

Exploitation of this vulnerability leads to a failure of the User-Data service, causing a disruption that requires a manual reset of the head unit's electronic control unit (ECU) to restore normal operation.

Reproduction

The vulnerability can be reproduced by connecting to a Mercedes-Benz NTG 6 head unit via the USB interface. Once connected, the 'UserData' service can be traced to monitor its activity. Afterward, the 'UserDataExchangeService' can be used to import user profile files from a USB storage device. During this process, the 'vt_ab.ud2' file, which is processed by the head unit's text-to-speech service, can be manipulated to trigger the vulnerability. The 'UserData' service will crash, causing the head unit to freeze and require a hard reset.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.5
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.