Unrated severityNVD Advisory· Published Jun 21, 2025· Updated Jun 23, 2025
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
CVE-2025-5476
Description
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the implementation of ACL-U links. The issue results from the lack of L2CAP channel isolation. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26284.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2.00.01
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-ax8500/software/00344092mitrevendor-advisory
- www.zerodayinitiative.com/advisories/ZDI-25-357/mitrex_research-advisory
News mentions
0No linked articles in our index yet.