Bluetooth Authentication Bypass Vulnerability in Sony XAV-AX8500
CVE-2025-5476

8.8HIGH

Key Information:

Vendor

Sony

Vendor
CVE Published:
21 June 2025

What is CVE-2025-5476?

The Sony XAV-AX8500 Bluetooth system is vulnerable to an authentication bypass due to improper isolation in L2CAP channel implementation. This flaw allows network-adjacent attackers to exploit the system without requiring authentication. By leveraging this vulnerability, attackers can potentially infiltrate the system, posing significant risks to user privacy and device security. It is essential for users to remain vigilant and monitor for any updates or patches provided by Sony to mitigate this risk.

Affected Version(s)

XAV-AX8500 2.00.01

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.