CVE-2025-5476: (Pwn2Own) Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the implementation of ACL-U links. The issue results from the lack of L2CAP channel isolation. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26284.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5476?
CVE-2025-5476 has been classified as a high-severity vulnerability due to its potential for exploitation without authentication.
How do I fix CVE-2025-5476?
To mitigate CVE-2025-5476, users should apply the latest firmware updates provided by Sony for the XAV-AX8500 device.
Who is affected by CVE-2025-5476?
CVE-2025-5476 affects users of the Sony XAV-AX8500 devices that have not been updated with the latest security patches.
What type of vulnerability is CVE-2025-5476?
CVE-2025-5476 is an authentication bypass vulnerability that allows network-adjacent attackers to exploit the affected devices.
Can CVE-2025-5476 be exploited remotely?
No, CVE-2025-5476 requires network adjacency for exploitation, meaning an attacker must be on the same network as the device.