CVE-2025-5820: (Pwn2Own) Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the implementation of Bluetooth ERTM channel communication. The issue results from improper channel data initialization. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26285.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5820?
The severity of CVE-2025-5820 is considered high, as it allows attackers to bypass authentication on affected devices.
How do I fix CVE-2025-5820?
To fix CVE-2025-5820, update your Sony XAV-AX8500 device with the latest firmware released by Sony.
What impact does CVE-2025-5820 have on the Sony XAV-AX8500?
CVE-2025-5820 impacts the Sony XAV-AX8500 by allowing unauthorized access through Bluetooth, compromising device security.
Who is affected by CVE-2025-5820?
Users of the Sony XAV-AX8500 are affected by CVE-2025-5820 due to the vulnerability in Bluetooth authentication.
Is authentication required to exploit CVE-2025-5820?
No, authentication is not required to exploit CVE-2025-5820, making it easier for attackers to target the device.