CVE-2025-67133
7.5Hero Motocorp · Vida V1 Pro
A denial of service vulnerability in the Hero Motocorp Vida V1 Pro 2.0.7 BLE component allows unauthenticated local attackers to disrupt system availability.
Executive summary
An unauthenticated local denial of service vulnerability in the Hero Motocorp Vida V1 Pro 2.0.7 firmware poses a significant risk to device availability.
Vulnerability
The vulnerability exists within the Bluetooth Low Energy (BLE) component, allowing an unauthenticated local attacker to trigger a denial of service condition.
Business impact
Successful exploitation of this vulnerability results in the denial of service for the affected vehicle's BLE functionality. Given the CVSS score of 7.5, this high severity flaw could lead to operational disruption of smart features and connectivity, potentially impacting user safety and vehicle management capabilities.
Remediation
Immediate Action: Monitor official communications from Hero Motocorp for firmware updates and apply them immediately upon release to resolve the BLE component flaw.
Proactive Monitoring: Observe vehicle connectivity logs for anomalous BLE connection attempts or unexpected resets of the infotainment system.
Compensating Controls: Disable Bluetooth connectivity on the vehicle when not in active use to minimize the attack surface available to local, proximity-based threats.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced security research.
Analyst recommendation
The reliance on BLE for vehicle features makes this denial of service vulnerability a priority for owners and fleet managers. Users should exercise caution regarding their physical environment and ensure that firmware updates are applied as soon as the vendor provides a remediation path to close this security gap.