CVE-2025-7020 is an incorrect encryption implementation vulnerability in the system log dump feature of BYD's DiLink 3.0 OS, affecting models like the ATTO3. An attacker with physical access to the vehicle can bypass encryption on the In-Vehicle Infotainment (IVI) unit's storage, allowing access to sensitive system logs containing PII and location data. This medium-severity vulnerability (CVSS 5.1) requires physical access and has a high impact on confidentiality. There is currently no public exploit code, active exploitation, or significant community discussion, and it was introduced in a patch for a previous CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| BYD | DiLink OS | 13.1.32.2307211.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:H/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.