Bluetooth Packet Handling Vulnerability in Sony XAV-AX8500 Devices
CVE-2025-5475

7.5HIGH

Key Information:

Vendor

Sony

Vendor
CVE Published:
21 June 2025

What is CVE-2025-5475?

The Sony XAV-AX8500 is susceptible to a vulnerability due to improper handling of Bluetooth packets, allowing network-adjacent attackers to execute arbitrary code. Attackers must pair a malicious Bluetooth device with the target system to exploit this flaw. The vulnerability arises from insufficient validation of user-supplied data, leading to an integer overflow that could be exploited to write to memory and execute code in the context of the elysian-bt-service process. This exposure highlights significant security risks for users relying on Bluetooth functionality.

Affected Version(s)

XAV-AX8500 2.00.01

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.