CVE-2025-67133

7.5

Hero Motocorp · Vida V1 Pro

A denial of service vulnerability in the Hero Motocorp Vida V1 Pro 2.0.7 BLE component allows unauthenticated local attackers to disrupt system availability.

Executive summary

An unauthenticated local denial of service vulnerability in the Hero Motocorp Vida V1 Pro 2.0.7 firmware poses a significant risk to device availability.

Vulnerability

The vulnerability exists within the Bluetooth Low Energy (BLE) component, allowing an unauthenticated local attacker to trigger a denial of service condition.

Business impact

Successful exploitation of this vulnerability results in the denial of service for the affected vehicle's BLE functionality. Given the CVSS score of 7.5, this high severity flaw could lead to operational disruption of smart features and connectivity, potentially impacting user safety and vehicle management capabilities.

Remediation

Immediate Action: Monitor official communications from Hero Motocorp for firmware updates and apply them immediately upon release to resolve the BLE component flaw.

Proactive Monitoring: Observe vehicle connectivity logs for anomalous BLE connection attempts or unexpected resets of the infotainment system.

Compensating Controls: Disable Bluetooth connectivity on the vehicle when not in active use to minimize the attack surface available to local, proximity-based threats.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced security research.

Analyst recommendation

The reliance on BLE for vehicle features makes this denial of service vulnerability a priority for owners and fleet managers. Users should exercise caution regarding their physical environment and ensure that firmware updates are applied as soon as the vendor provides a remediation path to close this security gap.

Sources