Bluetooth Packet Handling Vulnerability in Sony XAV-AX8500 Devices
CVE-2025-5475
7.5HIGH
What is CVE-2025-5475?
The Sony XAV-AX8500 is susceptible to a vulnerability due to improper handling of Bluetooth packets, allowing network-adjacent attackers to execute arbitrary code. Attackers must pair a malicious Bluetooth device with the target system to exploit this flaw. The vulnerability arises from insufficient validation of user-supplied data, leading to an integer overflow that could be exploited to write to memory and execute code in the context of the elysian-bt-service process. This exposure highlights significant security risks for users relying on Bluetooth functionality.
Affected Version(s)
XAV-AX8500 2.00.01
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published