Buffer Overflow in Bluetooth Stack of Bosch Infotainment ECU Used in Nissan Leaf
CVE-2025-32062

8.8HIGH

Key Information:

Vendor

Bosch

Vendor
CVE Published:
15 February 2026

What is CVE-2025-32062?

A vulnerability exists within the Bluetooth stack of the Infotainment ECU manufactured by Bosch for the Nissan Leaf ZE1 (2020). This issue arises from inadequate boundary validation of user-supplied data, leading to potential stack-based buffer overflow conditions when specific packets are received on the upper layer L2CAP channel. An attacker can exploit this flaw to execute remote code with root privileges on the affected Infotainment ECU system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Infotainment system ECU Linux 283C30861E

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mikhail Evdokimov (PCA Cyber Security Assessment Team)
.