CVE-2025-63895

7.5

JXL · 9 Inch Car Android Double Din Player

The Bluetooth firmware in the JXL 9 Inch Car Android Double Din Player contains a vulnerability that allows unauthenticated attackers to trigger a denial of service via crafted LMP packets.

Executive summary

A critical vulnerability in the JXL 9 Inch Car Android Double Din Player allows remote, unauthenticated attackers to cause a denial of service through crafted Bluetooth packets.

Vulnerability

The flaw exists within the Bluetooth firmware handling of Link Manager Protocol (LMP) packets. An unauthenticated remote attacker can exploit this by sending a specially crafted packet to the device, resulting in a denial of service state.

Business impact

This vulnerability carries a CVSS score of 7.5, reflecting its high impact on system availability. Successful exploitation would render the infotainment unit unresponsive, potentially causing loss of navigation, communication, and multimedia services for the vehicle operator, which poses a significant operational risk in automotive environments.

Remediation

Immediate Action: Contact the hardware manufacturer or the vehicle provider to determine if a firmware update is available for this specific infotainment unit.

Proactive Monitoring: Monitor the device for unexpected reboots or unresponsiveness that may correlate with proximity to unknown Bluetooth devices.

Compensating Controls: Disable Bluetooth functionality on the device if it is not required for daily operations to eliminate the attack surface.

Exploitation status

Public Exploit Available: Yes — a technical write-up and proof-of-concept are available via the referenced GitHub repository.

Analyst recommendation

Given the exposure of Bluetooth-enabled devices to remote attackers, users should prioritize obtaining firmware updates from the vendor. If an official patch is unavailable, disabling the Bluetooth interface is the most effective way to secure the device against this denial of service attack.

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Analyst report written

Sources