CVE-2025-7020
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
09/08/2025
Last modified:
11/08/2025
Description
An incorrect encryption implementation vulnerability exists in the system log dump feature of BYD&#39;s DiLink 3.0 OS (e.g. in the model ATTO3). An attacker with physical access to the vehicle can bypass the encryption of log dumps on the In-Vehicle Infotainment (IVI) unit&#39;s storage. This allows the attacker to access and read system logs containing sensitive data, including personally identifiable information (PII) and location data.<br />
<br />
This vulnerability was introduced in a patch intended to fix CVE-2024-54728.