Automotive

Spoofing

Static GPS spoofing on Infotainment System

Successful exploitation of this vulnerability allows an attacker to spoof a static GPS location on the JXL Infotainment System, causing the system to consistently display incorrect positioning…

9.1
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS100
PUBLISHED
2026-04-22
CVE IDs
CVE-2025-69515
VENDORS
JXL Infotainment
PUBLIC EXPLOIT
None indexed
CWE
CWE-941
PRODUCT
JXL 9 Inch Car Android Double Din Player
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

A vulnerability was identified in the GPS signal processing of the JXL Infotainment System, which relies on standard civilian GPS signals for location determination without performing sufficient validation or authenticity checks on the received data. Due to this lack of verification, an attacker in proximity can transmit forged GPS signals using a Software Defined Radio (SDR) device such as the HackRF One, mimicking legitimate satellite transmissions and overriding genuine signals. As a result, the infotainment system processes these spoofed inputs and computes an incorrect, attacker-controlled static location without detecting anomalies, leading to potential impacts such as inaccurate navigation, unintended geofencing behavior, and misuse of location-based functionalities, all without requiring direct access or authentication.

Vulnerability details

Vulnerability details

CVE-2025-69515
CWE-941
Critical | 9.1

A vulnerability was identified in the GPS signal processing of the JXL Infotainment System, which relies on standard civilian GPS signals for location determination without performing sufficient validation or authenticity checks on the received data.

Auth:
None (remote)
Impact:
Arbitrary data or code modification, denial of service
Impact

What an attacker can do

Successful exploitation of this vulnerability allows an attacker to spoof a static GPS location on the JXL Infotainment System, causing the system to consistently display incorrect positioning information. This can lead to inaccurate navigation routes, misleading map data, and unintended behavior in location-based features such as geofencing. As a result, the reliability of navigation and other GPS-dependent functionalities is reduced, which may impact user trust and, in certain scenarios, raise safety concerns.

DISCLOSURE

Disclosure timeline

2026-02-19 CVE ID Reserved

2026-04-08 CVE published

Credits

Shubham S. Thorat – Payatu Security Consulting Pvt. Ltd.