CVE-2025-69515
Received
Received - Intake
GPS Spoofing Vulnerability in JXL 9 Inch Android Player
Publication date: 2026-04-07
Last updated on: 2026-04-09
Assigner: MITRE
Description
Description
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jxl | 9_inch_car_android_double_din_player | 12.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-941 | The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor. |