CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Fuzzing tool finds denial-of-service bug in V2X message gateways

SNFuzz targets MQTT-SN gateways and lands a high-severity denial-of-service bug in the EMQX implementation.

CarThreat Staff
Last updated: August 13, 2026 10:58 pm
By
ctadmin
2 Min Read
SHARE

A team from Florida International University has built SNFuzz, a fuzzing framework aimed at MQTT-SN, the lightweight messaging protocol that vehicles and roadside systems increasingly use for V2X communication. Their first run found a high-severity denial-of-service vulnerability in the EMQX gateway, which they reported to the developers.

MQTT-SN is a UDP-based variant of MQTT designed for low-power, resource-constrained devices. The team argues its stateless transport and gateway-centric design creates extra attack surface, because gateways maintain implicit protocol state that attackers never see.

Connection-oriented fuzzers miss this hidden logic entirely. SNFuzz instead tracks the states a gateway juggles and drives execution from server responses, letting it probe deep state-dependent paths. Against three MQTT-SN gateway implementations, it beat existing network fuzzers on state coverage and reached protocol branches earlier tools never touched.

The findings, presented at VehicleSec ’26, highlight a broader problem: state-aware fuzzing is becoming essential for gateway-centric IoT protocols running over stateless transports, and vehicles are no exception as they evolve into connected systems relying on lightweight messaging.

With V2X deployment expanding, flaws in the middleware that moves safety-critical messages between cars and infrastructure carry outsized risk. The team says its results show how automated fuzzing can surface these bugs before attackers do.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityFirmware SecurityV2X CommunicationsVehicle SoftwareVulnerabilities
SOURCES:USENIX VehicleSec 2026
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Tata Sierra EV clears penetration tests for India’s AIS-189 rules

By
ctadmin
August 20, 2026
Cybersecurity

Identity-based crypto removes plaintext keys from CCS charging

By
ctadmin
August 12, 2026
AI Race

AI tool chains low-severity bugs into critical automotive attack paths

By
ctadmin
July 27, 2026
Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

By
ctadmin
August 26, 2026
Cybersecurity

Quantum-safe update handshake keeps low-power ECUs safe on the road

By
ctadmin
August 12, 2026
Cybersecurity

BYD’s New In-House Chip Reshapes Self-Driving Compute Strategy

By
ctadmin
May 30, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?