Command Injection Vulnerability in MIB3 Infotainment by VW
CVE-2023-28906
Key Information:
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2023-28906?
A command injection vulnerability resides within the networking service of the MIB3 infotainment system, putting at risk vehicles equipped with this unit. An attacker with access to the system can exploit this vulnerability to escalate privileges, gaining administrative access and potentially compromising vehicle operation. The issue was notably identified in the Skoda Superb III model, though other units with specific OEM part numbers are also affected. This risk underscores the need for robust security measures in automotive infotainment systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Volkswagen MIB3 infotainment system MIB3 OI MQB 0 <= 0304
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
