Modern vehicles are no longer purely mechanical machines. They are rolling computer networks, built from dozens of interconnected electronic control units.
Federal agencies, including the FBI, NHTSA, and the Department of Commerce, have repeatedly flagged this connectivity as a safety and security concern. Their warnings point to specific systems that, if compromised, could allow an outsider to access or manipulate a vehicle remotely.
These findings aren’t speculation. They’re based on documented research, real-world recalls, and formal government rulemaking. In 2015, security researchers famously took remote control of a moving Jeep Cherokee. That single demonstration triggered a 1.4-million-vehicle recall and a joint FBI-NHTSA public advisory the following year.
Since then, the list of flagged systems has only grown. Regulators have expanded their focus from individual components to entire vehicle connectivity architectures.
This article breaks down ten systems that government agencies have explicitly identified as remote-access risk points. Each one plays a legitimate role in modern driving. But each has also been named, in official reports or rulings, as a potential doorway into your vehicle’s most critical functions.
1. Telematics Control Units (TCUs)
The telematics control unit is the cellular brain of a connected car. It constantly talks to manufacturer servers over mobile networks. NHTSA’s 2016 cybersecurity bulletin specifically named telematics systems as a primary entry point for remote attacks. The agency noted that any wireless entry point tied to safety systems could count as a defect.
This isn’t theoretical. The 2015 Jeep hack exploited a vulnerability inside the vehicle’s telematics unit, called Uconnect. Researchers accessed the system over a cellular network from miles away. From there, they reached the CAN bus, the vehicle’s internal nervous system.

That access let them disable transmission and brakes. Fiat Chrysler was forced to recall roughly 1.4 million vehicles as a direct result. TCUs are attractive targets because they’re always connected. Unlike Bluetooth or Wi-Fi, cellular access doesn’t require physical proximity to the car.
An attacker anywhere with a data connection can theoretically reach a vulnerable TCU. This is precisely why the Commerce Department later classified vehicle connectivity systems, which include TCUs, as a national security concern.
Its 2025 final rule on connected vehicles explicitly cited the risk of foreign actors gaining remote access through this pathway. The rule restricts telematics hardware and software tied to China or Russia in vehicles sold in the U.S.
Officials warned that a hostile foreign actor could, in theory, disable large numbers of vehicles simultaneously through compromised telematics infrastructure. That scenario formed a central justification for the ban.
Automakers have since pushed extensive security patches to TCU firmware. Even so, regulators treat this component as one of the highest-priority attack surfaces in any modern vehicle.
2. The OBD-II Diagnostic Port
Every vehicle sold in the U.S. since 1996 has an OBD-II port. It sits under the dashboard and gives mechanics direct access to a car’s internal systems.
The FBI and NHTSA’s joint 2016 advisory called out this port by name. They warned that third-party devices plugged into it can introduce serious vulnerabilities.
These aftermarket dongles are common. Insurance companies use them to track driving habits, and fleet operators use them for monitoring. Many of these devices add their own cellular or Bluetooth connectivity. That’s where the danger multiplies.

A poorly secured dongle effectively becomes a second telematics unit, one that wasn’t designed with the same rigor as factory equipment. If it’s hacked, the attacker inherits its access to the vehicle’s internal network.
Government researchers demonstrated this risk directly. In tests cited by federal agencies, insurance-tracking dongles were shown to be exploitable, giving attackers a path to the CAN bus.
The OBD-II port itself isn’t wireless. But the devices routinely plugged into it often are, and that transforms a diagnostic tool into a remote access point.
Regulators have urged consumers to research any aftermarket OBD device before installation. They specifically recommend checking whether the manufacturer has a track record of security updates.
The core problem is structural. The port was designed for trusted mechanics with physical access, not for internet-connected consumer gadgets plugged in by anyone.
3. Keyless Entry and Remote Key Fobs
Keyless entry systems use short-range radio signals to lock, unlock, and sometimes start a vehicle. They’ve become standard across nearly every price bracket.
NHTSA has flagged these systems repeatedly, both for security and for unrelated safety issues like carbon monoxide poisoning from cars left running. But the cybersecurity angle is what concerns hacking researchers most.
The core vulnerability is called a relay attack. Two people with signal amplifiers can capture a key fob’s signal from inside a house and relay it to a car parked outside. The car interprets the amplified signal as the real key being nearby. It unlocks, and in many cases, allows the engine to start.

This isn’t a rare parlor trick. Insurance data and law enforcement reports across the U.S. and Europe have documented thousands of thefts using this exact method.
Some manufacturers have also had flaws in the rolling code systems meant to prevent signal replay. Researchers have shown that certain rolling codes could be predicted or captured and reused.
Federal safety officials have pushed automakers to adopt stronger encryption and motion-sensing fobs that stop transmitting when stationary. Some manufacturers now offer fobs with a physical off switch for this reason.
The government’s broader message is straightforward. Convenience features that eliminate physical keys also eliminate the physical barrier that once prevented remote unauthorized entry.
Until stronger standards are mandated industry-wide, keyless entry remains one of the most commonly exploited remote-access systems on ordinary vehicles.
4. Tire Pressure Monitoring Systems (TPMS)
Every new car sold in the U.S. must have a tire pressure monitoring system by federal mandate. Each wheel has a sensor that wirelessly transmits pressure data to the dashboard. It sounds harmless. But government-funded researchers have shown TPMS sensors can be exploited for more than just spoofing a warning light.
A 2010 study, later referenced in subsequent NHTSA cybersecurity assessments, demonstrated that TPMS sensors could be used to track a vehicle’s location. Each sensor broadcasts a unique ID that can be picked up from a distance.

That means a vehicle can potentially be tracked and fingerprinted just by monitoring its tire sensor broadcasts. No physical access to the car is required.
Researchers also showed that spoofed TPMS signals could trigger false warnings on a dashboard. While this doesn’t hand over control of steering or brakes, it demonstrates that even minor sensor systems have real remote attack surfaces.
NHTSA’s broader cybersecurity guidance treats TPMS as part of the larger wireless attack surface, not a system to dismiss. Any wireless sensor network on a vehicle expands the number of doors an attacker might find open.
The agency’s position is that low-risk systems can still be strung together for bigger attacks. A compromised TPMS sensor alone may seem trivial.
But combined with weaknesses elsewhere in a vehicle’s network, it becomes one more piece of a larger security puzzle that regulators want automakers to close.
Also Read: 10 Signs a Car Is Sending Data Right Now
5. Infotainment and Head Unit Systems
The touchscreen in the center console does far more than play music now. It runs navigation, phone pairing, voice assistants, and often controls climate and vehicle settings too.
This system, commonly called the head unit, was the exact target in the landmark Jeep Cherokee hack. Researchers entered through Uconnect and pivoted from there into safety-critical systems.
NHTSA’s cybersecurity bulletin specifically discusses infotainment systems as high-risk entry points. The agency notes that a vulnerability here becomes especially dangerous if the infotainment system is connected to the same internal network as steering or braking controls.

That network separation, or lack of it, is a recurring theme in federal guidance. Automakers are now strongly encouraged to isolate infotainment from safety-critical systems using network segmentation.
Not all manufacturers had this separation in earlier vehicle generations. That gap is exactly what allowed the 2015 researchers to move from the entertainment system into engine and brake controls.
Infotainment systems also run app stores, browsers, and third-party integrations. Each of these adds more code, and more code means more potential vulnerabilities.
Government researchers have pointed out that infotainment software is rarely updated as rigorously as smartphone operating systems. Patches can lag for months or years after a vulnerability is disclosed.
Because these systems are Bluetooth and Wi-Fi enabled, and often cellular connected too, they represent multiple wireless doors in a single unit. Regulators consider this convergence one of the most concerning designs in the modern connected car.
6. In-Vehicle Wi-Fi Hotspots
Many vehicles now ship with built-in Wi-Fi hotspots, letting passengers connect phones, tablets, and laptops on long drives. It’s marketed as a premium convenience feature.
Federal cybersecurity guidance treats these hotspots the same way it treats home or office Wi-Fi routers. They can be scanned, probed, and in some cases breached remotely.
NHTSA’s bulletin explicitly lists Wi-Fi as one of the wireless entry points that can expose critical vehicle systems to remote attackers. If a hotspot uses weak or outdated encryption, nearby attackers could gain network access.

Once inside that network, the concern is the same as with infotainment systems. Depending on internal network design, a breach of Wi-Fi could open a path toward more sensitive vehicle systems.
Security researchers have also raised concerns about default passwords on vehicle Wi-Fi systems. Some owners never change factory settings, leaving hotspots easier to access than intended.
Unlike a home router, a vehicle’s Wi-Fi hotspot is mobile. That means its signal, and its vulnerabilities, travel with the car into parking lots, driveways, and public spaces.
Government researchers have noted this creates a broader footprint for potential attackers than a stationary network would. Anyone within range at any given moment becomes a possible threat.
Automakers have responded with stronger encryption standards and periodic password resets in newer models. But regulators continue to list vehicle Wi-Fi among systems requiring ongoing security scrutiny.
7. Vehicle Connectivity Systems (VCS)
This is a newer, broader category defined by the Commerce Department in its 2025 connected vehicle rule. It bundles Bluetooth, cellular, satellite, and Wi-Fi modules into a single regulated system.
The rule’s language is direct. It states that VCS hardware and software can allow remote access to vehicles, and that hostile actors could exploit this to disrupt or control them.
Commerce officials described a scenario where a foreign adversary could shut down or take control of many vehicles simultaneously. That statement came directly from Secretary Gina Raimondo during the rule’s announcement.

This isn’t about one flaw in one part. It’s about the entire communications architecture that lets a car talk to the outside world.
The rule specifically restricts VCS hardware and software with ties to China or Russia, citing national security risk rather than a single technical vulnerability. It reflects a shift in government thinking.
Older warnings, like the 2016 FBI-NHTSA advisory, focused on criminal hackers exploiting individual components. The VCS rule instead treats connectivity itself, at a systemic level, as a geopolitical risk.
The final rule took effect starting with software in the 2027 model year, with hardware restrictions following later. It excludes trucks and buses for now, which regulators say will be addressed separately.
This system matters because it formalizes something researchers had argued for years. Every wireless module in a car is part of one interconnected attack surface, not a set of isolated features.
8. Automated Driving System (ADS) Software
Advanced driver assistance features, and the fuller autonomous driving software stacks some vehicles now run, were explicitly named in the same Commerce Department rule as VCS. Regulators paired the two because they often share infrastructure.
ADS software processes data from cameras, radar, and lidar to make real-time driving decisions. In more advanced systems, it can control steering, acceleration, and braking without direct driver input.
The government’s stated concern isn’t just about ADS malfunctioning on its own. It’s about that software being remotely manipulated through connected pathways it shares with telematics and cellular modules.
If VCS provides the doorway, ADS is one of the rooms regulators worry about someone walking into. A compromised automated driving system could, in theory, be fed false sensor data or have commands overridden remotely.

This is a newer and less publicly tested risk than older systems on this list. Full ADS deployment is still limited, which means fewer real-world attack demonstrations exist compared to infotainment or keyless entry.
But the Commerce Department treated it seriously enough to include restrictions on ADS software with ties to China or Russia in the same rule governing connectivity hardware. Officials explicitly linked ADS software risk to the possibility of remote sabotage affecting vehicle safety.
NHTSA has separately published cybersecurity best-practice guidance urging manufacturers to build strong authentication between ADS components and any external communication system. The agency wants a hard line between decision-making software and outside networks.
As more vehicles adopt advanced driving assistance, government attention to this specific system is expected to grow. It sits at the intersection of software security and physical vehicle control.
9. Manufacturer Remote Apps
Nearly every major automaker now offers a smartphone app that can lock, unlock, locate, and even start a vehicle remotely. These apps have become a standard selling point.
Consumer protection and cybersecurity researchers, whose findings federal agencies have cited in public guidance, have documented real vulnerabilities in several of these apps. Some allowed unauthorized users to locate or unlock vehicles that weren’t theirs.
In one widely reported case, a researcher found that a manufacturer’s app programming interface could be manipulated to access other customers’ vehicle data. This included location history and remote start capability.

The FBI and NHTSA’s original 2016 advisory touched on this risk category too, even before these apps were as widespread as they are now. It warned that remote features tied to a vehicle, including remote start, expand the ways an outsider might interfere.
The core issue with these apps isn’t the vehicle’s hardware at all. It’s the cloud account behind it, the same weak point that affects email or banking apps.
If an attacker compromises a driver’s manufacturer account through phishing or a data breach, they may inherit that account’s vehicle privileges. That can include unlocking doors or tracking real-time location.
Federal guidance recommends multi-factor authentication on these accounts, something not all automakers enabled by default in earlier app versions. Regulators have pushed the industry to close this gap.
Because these apps operate through the same cellular telematics infrastructure named earlier in this list, they represent a user-facing extension of that risk. A weak app is often the easiest way into an otherwise well-secured car.
10. The CAN Bus and Electronic Control Unit Network
Underneath every system on this list sits the Controller Area Network, or CAN bus. It’s the internal communication highway that lets a car’s dozens of electronic control units talk to each other.
NHTSA’s cybersecurity bulletin treats the CAN bus as the ultimate target behind every wireless entry point. Steering, braking, acceleration, airbags, and door locks all send and receive commands across it.
The problem, as government researchers have explained, is that CAN bus architecture in most vehicles wasn’t originally designed with security in mind. It assumes any message on the network is legitimate.
That means once an attacker breaches any wireless entry point, whether telematics, infotainment, or a rogue OBD-II dongle, and reaches the CAN bus, they can potentially send commands to critical systems. This was exactly the path used in the 2015 Jeep demonstration.

Researchers didn’t need to hack the brakes directly. They hacked the entertainment system, then rode the internal network straight to the brakes.
This is why NHTSA’s guidance pushes automakers toward network segmentation and intrusion detection systems for the CAN bus itself. The agency wants gateways that prevent infotainment traffic from ever reaching safety-critical control units.
Some manufacturers have begun implementing these firewalls in newer models. Older vehicles, and some current ones, still run flatter network architectures where a single breach can cascade.
Government agencies consistently describe the CAN bus as the system that turns individual vulnerabilities into serious safety incidents. Every other item on this list matters largely because of what it connects to here.
Also Read: 4 Three-Row SUVs Worth the Money vs 4 Overpriced Ones
