Sidechat icon
Join communities on Sidechat Download
I DID IT! I have managed to get arbitrary root code execution and dump the encrypted file system on the latest version of my 2025 Kia CCNC head unit! This took a few months and was a hell of a journey. I have learned so much. Next up... persistence.
9 upvotes, 8 comments. Sidechat image post by Anonymous in Computer Science. "I DID IT! I have managed to get arbitrary root code execution and dump the encrypted file system on the latest version of my 2025 Kia CCNC head unit!

This took a few months and was a hell of a journey. I have learned so much. Next up... persistence."
upvote 9 downvote

default user profile icon
Anonymous 1d
post
upvote 5 downvote
default user profile icon
Anonymous 1d

This exploited a flaw in the USB updater system and the way it handles .zip files, allowing me to write any file anywhere as root. Unfortunately, every directory but 2 are mounted as RO and cryptographically signed, and there (seemed to be) nothing executable to overwrite on the 2 that are RW, they mostly just store cache files and user settings.

upvote 3 downvote
default user profile icon
Anonymous 1d

Also the only way to see anything is from the diagnostic logs in dealer mode, which are limited and take ~15 minutes to export to a USB. So I'd have to make 1 change, plug it in, let it run the update process for ~10 minutes, and then export the log which took another 15, and then go connect it to my PC to see if that change worked... painfully slow process lmao

upvote 1 downvote
default user profile icon
Anonymous 23h

You said this is an exploit right? are you going to show this to kia for a bounty?

upvote 1 downvote
default user profile icon
Anonymous 16h

I'm learning how to exploit rn, this is really cool

upvote 1 downvote
default user profile icon
Anonymous replying to -> OP 1d

Get SHREKT Kia!

upvote 6 downvote
default user profile icon
Anonymous replying to -> #1 21h

Kia doesn't offer bounties, and was actually hostile against the last dude that reported one, so no. They can kiss my ass. This is gonna be used to pirate the dashboard themes they sell instead, because charging $40 just to change my dashboard profile pic to Darth Vader on a car I ALREADY PAID 50K FOR is criminal

upvote 1 downvote
default user profile icon
Anonymous replying to -> OP 21h

honestly i wish cars were more customizable but i also can see the security issue. I want my instrument clusters to be displayed one way but at most all i can do is change one small little info container 😕. But yeah unfortunate kia is that way

upvote 1 downvote