Bluetooth Authentication Bypass Vulnerability in Sony XAV-AX8500 Devices
CVE-2025-5820
8.8HIGH
What is CVE-2025-5820?
A vulnerability in the Sony XAV-AX8500 allows attackers on the same network to bypass authentication due to inadequate initialization of Bluetooth ERTM channel communication. This flaw enables unauthorized access to device functions without requiring proper credentials, posing a significant security risk to users.
Affected Version(s)
XAV-AX8500 2.00.01
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published