AI 中文总结
本文通过逆向工程分析商用车辆制动ECU固件更新,利用QBinDiff对S12X架构固件镜像做差异二进制分析,发现召回措施的补丁存在关键缺陷,该召回修复兼具安全补丁属性。
AI 中文摘要
本文对商用车辆制动ECU的固件更新开展逆向工程分析,我们解析更新程序可执行文件以提取固件,并对S12X架构固件镜像执行差异二进制分析。研究识别出召回措施中针对旧协议处理未公开漏洞的具体变更,证实补丁功能存在关键缺陷,且此次安全召回修复同时也是一次安全补丁。
英文摘要
This paper presents a reverse engineering analysis of a firmware update for a commercial vehicle Brake ECU. We analyze the updater executable to extract firmware and perform differential binary analysis of the S12X architecture firmware images. Our research identifies specific changes in the recall that address undocumented vulnerabilities in legacy protocol processing. We demonstrate that the patched functionality contained critical flaws. The findings confirm the safety recall remediation was also a security patch.
CommentsPreprint of paper to be presented at VehicleSec 2026. This version includes appendices beyond the page limits of the conference