The specific flaw exists within the implementation of ACL-U links. The issue results from the lack of L2CAP channel isolation. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26284.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18881 | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of ACL-U links. The issue results from the lack of L2CAP channel isolation. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26284. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sony
Sony xav-ax8500 Sony xav-ax8500 Firmware |
|
| CPEs | cpe:2.3:h:sony:xav-ax8500:-:*:*:*:*:*:*:* cpe:2.3:o:sony:xav-ax8500_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sony
Sony xav-ax8500 Sony xav-ax8500 Firmware |
|
| Metrics |
cvssV3_1
|
Mon, 23 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 21 Jun 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of ACL-U links. The issue results from the lack of L2CAP channel isolation. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26284. | |
| Title | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability | |
| Weaknesses | CWE-653 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2025-06-23T14:47:12.400Z
Reserved: 2025-06-02T19:14:36.601Z
Link: CVE-2025-5476
Updated: 2025-06-23T14:47:09.187Z
Status : Analyzed
Published: 2025-06-21T01:15:28.193
Modified: 2025-07-08T14:30:24.420
Link: CVE-2025-5476
No data.
OpenCVE Enrichment
No data.
EUVD