PlaxidityX Threat Labs has detailed a vulnerability in the Tesla Model 3 and Model Y that enabled keyless car theft via CAN injection attacks. Tracked as CVE-2025-6785, the flaw allowed attackers to inject malicious CAN messages into the vehicle network without key-based authentication or physical interior access.
Researchers connected a homemade device to the OBD-II port behind the rear seat and sent commands over the CAN bus to shift the car into drive and start the engine. The attack exploited the fact that in modern keyless entry systems, virtually all authentication occurs over the network, with no physical key mechanism required to start the vehicle.
UK data shows that 58% of vehicle thefts between April 2023 and March 2024 involved keyless techniques. The Tesla case study demonstrates that even industry-leading vehicles with advanced software security remain vulnerable to CAN bus injection attacks.
Tesla independently discovered the issue before disclosure and released firmware version 2023.44, which renders this specific theft method ineffective. However, the research highlights a broader industry challenge as keyless car theft continues to surge across North America and Europe.
PlaxidityX recommends OEMs adopt proactive, real-time anti-theft solutions that monitor CAN bus traffic for unauthorized injection patterns, rather than relying solely on factory-installed immobilizers and encryption.