CRITICAL🇵🇱 Wersja polska

CVE-2025-69515

CVSS 9.1v3.1pub. 2026-04-07upd. 2026-07-24

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

🤖 AI Analysis
How it works

An attacker can deliver spoofed GPS signals to the infotainment system, which the device accepts without proper verification of their authenticity (CWE-941: Incorrect Selection of Fuse or Latch Input). The system cannot distinguish legitimate signals from false ones, allowing substitution of actual location data. The result is the device displaying incorrect or frozen geographic position.

Impact

An attacker can cause the infotainment system to report false or static vehicle location, which may mislead the driver and disrupt navigation. The vulnerability has potential impact on vehicle user safety in situations dependent on accurate GPS data.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. It is recommended to contact the manufacturer (jxl.com) to obtain firmware updates and avoid using GPS navigation on devices running the vulnerable version.

Who is affected

JXL 9 Inch Car Android Double Din Player with Android v12.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References