Date: 2021-12-23
Generic Manufacturer
NHTSA Action Number: DP21005
Components: ELECTRICAL SYSTEM: INSTRUMENT CLUSTER/PANEL
Subject: SAE J1939 Data Bus Vulnerability
Opened From: 2021-12-23 - 2022-02-07
Summary
In a letter dated September 27, 2021, Mr. James Lamb, Executive Director of the Small Business in Transportation Coalition (SBTC), petitioned the National Highway Traffic Safety Administration (NHTSA), requesting the initiation of a defect investigation into the potential hacking susceptibility of the Society of Automotive Engineers (SAE) J1939 Data Bus standard. SAE J1939 is the vehicle bus recommended practice used for communication and diagnostics among vehicle components. In support of the petition, the petitioner cited a study from University of Michigan (Michigan) researchers alleging a SAE J1939 Data Bus vulnerability in a Model Year (MY) 2001 school bus and a MY 2006 Class-8 semi-tractor. The study alleges that, due to the vulnerability, vehicle critical safety functions such as the accelerator control or braking systems are susceptible to unauthorized access and control and increases risk to motor vehicle safety. On December 23, 2021, the Office of Defects Investigation (ODI) opened DP21-005 to evaluate the petitioner's request. The petitioner did not specify the make and model of the vehicles with the alleged safety defect. The only categories of relevant vehicles specified were found in the study: MY 2001 school buses and MY 2006 Class-8 semi-tractors. ODI has not received any complaints of any type related to this alleged vulnerability (The single complaint identified above is the petition.). This evaluation included searches of complaints from vehicle owners, operators, and fleet supervisors.Further, based on the available information, ODI has not found any similar events/complaints/allegations suggesting a real-life vulnerability. The vehicle compromises reported in the Michigan study required physical access to the J1939 connector in order to affect vehicle critical safety functions such as the accelerator control or braking systems. Whether there is a potential for remote compromise is a factor that NHTSA has considered in evaluating the likelihood or frequency of a potential safety defect. The Michigan study did not demonstrate a remote compromise of these vehicles. In addition, based on the age of the subject model year school buses and semi-tractors, they do not have over-the-air software update capabilities/internet connection to make remote compromise possible. Therefore, given a thorough analysis of the potential for finding a safety-related defect in the subject vehicles, and in view of NHTSA?s enforcement priorities, a defects investigation is unlikely to result in a finding that a defect related to motor vehicle safety exists. NHTSA is authorized to issue an order requiring notification and remedy of a defect if the Agency's investigation shows a defect in the design, construction, or performance of a motor vehicle that presents an unreasonable risk to safety (49 U.S.C. ?? 30102(a)(9), 30118).Given the absence of any similar events/incidents related to this matter and lack of demonstrated potential for remote compromise, it is unlikely that an order concerning the notification and remedy of a safety-related defect would be issued due to any investigation opened as a result of granting this petition. Therefore, upon full consideration of the information presented in the petition, and the potential risks to safety, the petition is denied. The denial of this petition does not foreclose the Agency from taking further action if warranted, or the potential for a future finding that a safety-related defect exists based upon additional information the Agency may receive. A notice of denial of this petition will be published in the Federal Register.
Investigation Documents
For Latest Documents related to this Investigation, visit the NHTSA Website.
Click the (+) Plus Sign
Then click Associated Document(s).
- Advanced VCI Box, Industry-leading J2534 Pass-Thru...
- High-Speed OEM-Level Diagnostics & Programming: Unlock true...
- Coverage for 17 Car Brands & Ultra Reliability: Works...
- User-Friendly RLink Platform & Expert Support: TOPDON’s...
- 6.6 ft USB-C Cable & Portable Storage Case: The RLink J...
Search NHTSA Database for Recalls
Search NHTSA Database for (TSB's) Technical Service Bulletins
Technical Service Bulletins TSB's List
Previous Investigation | Next Investigation |
- CEL Doctor: The ANCEL AD310 is one of the best-selling OBD II scanners on the market and is recommended by Scotty Kilmer, a YouTuber and auto mechanic. It can easily determine the cause of the check engine light coming on. After repairing the vehicle's problems, it can quickly read and clear diagnostic trouble codes of emission system, read live data & hard memory data, view freeze frame, I/M monitor readiness and collect vehicle information.
- Sturdy and Compact: Equipped with a 2.5 foot cable made of very thick, flexible insulation. It is important to have a sturdy scanner as it can easily fall to the ground when working in a car. The AD310 OBD2 scanner is a well-constructed mechanic tool with a sleek design. It weighs 12 ounces and measures 8.9 x 6.9 x 1.4 inches. Thanks to its compact design and light weight, transporting the device is not a problem. The buttons are clearly labelled and the screen is large and displays results clearly.
- Accurate Fast and Easy to Use: The AD310 scanner can help you or your mechanic understand if your car is in good condition, provides exceptionally accurate and fast results, reads and clears engine trouble emission codes in seconds after you fixed the problem. This device will let you know immediately and fix the problem right away without any car knowledge. No need for batteries or a charger, get power directly from the OBDII Data Link Connector in your vehicle.
- OBDII Protocols and Car Compatibility: Many cheap scan tools do not really support all OBD2 protocols. AD310 scanner as it can support all OBDII protocols such as KWP2000, J1850 VPW, ISO9141, J1850 PWM and CAN. This device also has extensive vehicle compatibility with 1996 US-based, 2000 EU-based and Asian cars, light trucks, SUVs, as well as newer OBD2 and CAN vehicles both domestic and foreign. Pls confirm with our customer service whether it is compatible with your vehicle before purchasing.
- Home Necessity and Worthy to Own: This is an excellent code reader to travel or home with as it weighs less and it is compact in design. You can easily slide it in your backpack as you head to the garage, or put it on the dashboard, this will be a great fit for you. The AD310 is not only portable, but also accurate and fast in performance. Moreover, it covers various car brands and is suitable for people who just need a code reader to check their car.
- Multi-Functions - Practical Multi-Functions OBD2 code reader features built-in OBD2 DTC lookup library, which help you to determine the cause of the engine light, read code, erase code, view freeze frame, I/M ready, vehicle information, data flow, real-time curve, get vehicle speed information, calculate load value, engine coolant temperature, get engine speed.
- Wide Capability - Supports 9 protocols compatible with most 1996 US-Based, 2000 EU-Based and Asian cars, and newer OBD II & CAN domestic or import vehicles. Supports 6 languages - English,German, Dutch, Spanish, French, Italian.
- 2.8" LCD Display - Designed with a clear display 2.8" Large LCD screen - white backlight and contrast adjustment. No need any battery or charger, OBD reader gets the power directly from your vehicle through the OBDII Data Link Connector.
- Compact Design - Car diagnostic scanner is equipped with a 2.5 feet long cable and made of a very thick flexible insulator.There are 6 buttons on OBD2 Scanner:scroll up/down,enter/exit and buttons that quick query VIN vehicle number& the DTC fault code.
- ABS / Airbag codes NOT Supported - It is able to read and clear check engine information which is part of OBDII system, but it cannot work with non-OBDII systems, including ABS / Airbag / Oil Service Light, etc.
- 【Your Personal CEL Doctor – Read & Clear Engine Codes】The NT301 OBD2 scanner lets you read diagnostic trouble codes (DTCs), check em-issions readiness, turn off your Check Engine Light (CEL) or MIL, reset monitors, and view live data streams. It retrieves your vehicle's VIN instantly. Like all standard OBD2 scanners, it clears codes only after repairs are completed—if the issue persists, the code will return. Designed for DIYers who want to understand what’s really going on under the hood.
- 【Easy Code Reading – Just Plug & Play】Simply plug into the OBD2 port, turn the ignition to “ON” (engine off), and select the correct menu: Select OBDII-> Wait for seconds-> Select Read codes. For accurate results, ensure your vehicle is compatible and the OBD2 port is free from damage or wiring issues. No batteries needed— powered directly by your car.
- 【Live Data Graphing & Accuracy for Most OBD2 Vehicles】View and log live sensor data in graph form—monitor oxygen sensors, fuel trims, coolant temp, RPM, and more. Spot trends and suspicious values in real time. Compatible with most 1996+ gasoline cars, light trucks, and SUVs sold in the U.S., as well as many 2000+ European and Asian models. Also works on 12V diesel vehicles equipped with OBD2.
- 【S-mog Check Helper – Know Your Readiness Status at a Glance】With dedicated I/M readiness hotkeys and a simple Red-Yellow-Green LED indicator, you’ll instantly know if your vehicle is ready for em-issions testing. Built-in speaker provides audio feedback. No guesswork—just confidence before you head to the test center.
- 【A Must-Have Tool for Every Home Mechanic】Compact, rugged, and ready to use right out of the box. The 2.8” color screen is easy to read, even in daylight. No charging or setup required—just plug into the 16-pin DLC and start diagnosing. Recommended by professional mechanics on YouTube and trusted by DIYers worldwide.
Last update on 2026-03-20 / Affiliate links / Images from Amazon Product Advertising API
This product presentation was made with AAWP plugin.





