An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.
The vulnerability (CWE-307) consists of the lack of a mechanism to limit excessive authentication attempts (no account lockout, CAPTCHA, request limit, or similar protections). An attacker can repeatedly send login requests, systematically testing combinations of credentials until gaining access. Since the attack requires no user interaction or prior privileges, it can be carried out entirely remotely.
Successful execution of the attack gives the attacker full access to the BYD vehicle's headunit system, which may result in breach of confidentiality, integrity, and availability of system data and functions — including potentially vehicle-related functions.
Apply patches available from the manufacturer according to references (byd.com, bydauto.com.cn). Until an update is applied, it is recommended to isolate the system from untrusted networks and monitor login attempts. Vulnerability details are available in the repository: https://github.com/zgsnj123/BYD_headunit_vuls/tree/main
BYD Dilink Headunit System in versions v3.0 to v4.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H