Buffer Overflow in Bluetooth Stack of Bosch Infotainment ECU Used in Nissan Leaf
CVE-2025-32062
8.8HIGH
What is CVE-2025-32062?
A vulnerability exists within the Bluetooth stack of the Infotainment ECU manufactured by Bosch for the Nissan Leaf ZE1 (2020). This issue arises from inadequate boundary validation of user-supplied data, leading to potential stack-based buffer overflow conditions when specific packets are received on the upper layer L2CAP channel. An attacker can exploit this flaw to execute remote code with root privileges on the affected Infotainment ECU system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Infotainment system ECU Linux 283C30861E
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mikhail Evdokimov (PCA Cyber Security Assessment Team)