CVE-2025-63896 is a high-severity vulnerability (CVSS 7.6) affecting the JXL 9 Inch Car Android Double Din Player (v12.0) and its firmware, allowing attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device. This adjacent network attack requires no user interaction and can lead to low confidentiality, high integrity, and low availability impacts. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the FAUCET Risk Score of 85/100 indicates a significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0CPE matchmatch criteria | cpe:2.3:o:jxlindia:jxl_9_inch_car_android_double_din_player_firmware:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.