Automotive

Authentication & Access Bypass

Wireless Key Stroke Injection on vehicle Infotainment

Successful exploitation allows an attacker within Bluetooth range to inject unauthorized keystrokes into the infotainment system.

7.6
/ 10
High
CVSS v3.1
ADVISORY ID
PS94
PUBLISHED
2025-12-08
CVE IDs
CVE-2025-63896
VENDORS
JXL Infotainment
PUBLIC EXPLOIT
PoC public
CWE
CWE-306
PRODUCT
JXL 9 Inch Car Android Double Din Player
CVSS VECTOR
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

A vulnerability was identified in the Bluetooth Human Interface Device (HID) handling mechanism of the infotainment system running Android v12.0. The BLE stack and input processing components accept peripheral devices with insufficient verification, allowing a spoofed HID device to be recognized as a legitimate input source. As a result, the system may process unsolicited keystroke inputs originating from external, non-trusted wireless devices. This behavior exposes the infotainment unit to unauthorized interaction through its BLE Interface.

Vulnerability details

Vulnerability details

CVE-2025-63896
CWE-306
High | 7.6

A vulnerability was identified in the Bluetooth Human Interface Device (HID) handling mechanism of the infotainment system running Android v12.0.

Auth:
None (adjacent network)
Impact:
Limited data disclosure, arbitrary data or code modification, partial service degradation
Impact

What an attacker can do

Successful exploitation allows an attacker within Bluetooth range to inject unauthorized keystrokes into the infotainment system. This can lead to unintended menu navigation, application launches, setting modifications, and interaction with system features without user consent. Although it does not directly affect other vehicle ECUs, it poses a significant risk by enabling remote manipulation of infotainment functions.

DISCLOSURE

Disclosure timeline

2025-09-23 Reported to Vendor

2025-11-20 CVE ID Reserved

2025-12-05 CVE published

Credits

Shubham S. Thorat – Payatu Security Consulting Pvt. Ltd.