Automotive

Denial of Service

Bluetooth Classic LMP Handle Flaw Exploitation

The vulnerability affects the stability and reliability of the vehicle's infotainment system by allowing unauthenticated Bluetooth Classic traffic to interact with low-level protocol handling.

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS95
PUBLISHED
2025-12-15
CVE IDs
CVE-2025-63895
VENDORS
JXL Infotainment
PUBLIC EXPLOIT
None indexed
CWE
CWE-404
PRODUCT
JXL 9 Inch Car Android Double Din Player
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

The infotainment unit uses a Bluetooth Classic (BR/EDR) chipset that contains a flaw in how it processes low-level LMP control messages during wireless communication. Due to improper validation of these packets, the Bluetooth controller inside the infotainment system can be pushed into an invalid or unexpected state when it receives malformed or out-of-sequence control messages from a nearby device.

Vulnerability details

Vulnerability details

CVE-2025-63895
CWE-404
High | 7.5

The infotainment unit uses a Bluetooth Classic (BR/EDR) chipset that contains a flaw in how it processes low-level LMP control messages during wireless communication.

Auth:
None (remote)
Impact:
Denial of service
Impact

What an attacker can do

The vulnerability affects the stability and reliability of the vehicle's infotainment system by allowing unauthenticated Bluetooth Classic traffic to interact with low-level protocol handling. Since the issue occurs at the LMP controller layer, malformed control messages can be processed before any pairing or authentication takes place. As a result, the infotainment unit may enter an unstable state, leading to crashes, denial-of-service conditions, or sudden reboots triggered by external, non-trusted Bluetooth devices. This behavior exposes the system to unauthenticated disruption through its Bluetooth Classic interface.

DISCLOSURE

Disclosure timeline

2025-09-23 Reported to Vendor

2025-11-20 CVE ID Reserved

2025-12-11 CVE published

Credits

Shubham S. Thorat – Payatu Security Consulting Pvt. Ltd.