CVE-2025-63896

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
04/12/2025
Last modified:
22/01/2026

Description

An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:jxlindia:jxl_9_inch_car_android_double_din_player_firmware:12.0:*:*:*:*:*:*:*
cpe:2.3:h:jxlindia:jxl_9_inch_car_android_double_din_player:-:*:*:*:*:*:*:*