Threat Intelligence / CVE / CVE-2025-8321

CVE-2025-8321 — Tesla Wall Connector

CVSS v3.1 6.8 (MEDIUM) · EPSS 0.3% (higher than 29.8% of all scored CVEs) · Priority 6.6/10 · Published 2025-07-30

As of 2025-07-30, CVE-2025-8321 is a MEDIUM-severity vulnerability in Tesla Wall Connector, CVSS v3.1 6.8, EPSS 0.3% (29.8th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2025-8321, most recently “Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector”.

Last updated: 2025-07-30

What is CVE-2025-8321?

Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware upgrade feature. The issue results from the lack of an anti-downgrade mechanism. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the device. Was ZDI-CAN-26299.

The record classifies CVE-2025-8321 under weakness class CWE-1328. Its CVSS v3 base vector states that the flaw requires physical access to the device, needs no prior authentication, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 409 days ago.

Severity and exploitation probability

CVSS v3.1 base score
6.8 — MEDIUM
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS (FIRST)
0.3% probability of exploitation in the next 30 days, higher than 29.8% of all scored CVEs
CISA KEV
Not listed in the CISA Known Exploited Vulnerabilities catalog
Threadlinqs priority
6.6/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
Published
2025-07-30

Is CVE-2025-8321 being exploited?

Weaponised exploit code for CVE-2025-8321 is publicly available. 1 public proof-of-concept repository is tracked for this identifier.

Affected products and versions

How to fix CVE-2025-8321

No vendor patch reference has been recorded for CVE-2025-8321 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

Threat activity tracking CVE-2025-8321

1 tracked threat in the Threadlinqs corpus references CVE-2025-8321, either in the campaign’s CVE list or as an indicator on the campaign record.

Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories, public proof-of-concept repositories. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.

Other references

Full detection coverage & IOCs for threats exploiting CVE-2025-8321 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence