CVE-2025-7020

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
09/08/2025
Last modified:
11/08/2025

Description

An incorrect encryption implementation vulnerability exists in the system log dump feature of BYD&amp;#39;s DiLink 3.0 OS (e.g. in the model ATTO3). An attacker with physical access to the vehicle can bypass the encryption of log dumps on the In-Vehicle Infotainment (IVI) unit&amp;#39;s storage. This allows the attacker to access and read system logs containing sensitive data, including personally identifiable information (PII) and location data.<br /> <br /> This vulnerability was introduced in a patch intended to fix CVE-2024-54728.

References to Advisories, Solutions, and Tools