CVE-2025-32061Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper layer L2CAP channel. An attacker can leverage this vulnerability to obtain remote code execution on the Infotainment ECU with root privileges. First identified on Nissan Leaf ZE1 manufactured in 2020.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-17); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-15: 1Mentions · 2026-02-16: 1Mentions · 2026-02-17: 3Mentions · 2026-02-20: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 3Technical Details · 2026-02-20: 102-1502-1602-1702-20
Signal classification1 categories
Disclosure
6100.0%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-151
Disclosure1
2026-02-161
Disclosure1
2026-02-173
Disclosure3
2026-02-201
Disclosure1
Full discourse6 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 17, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. CVE-2026-2553: SQL Injection in tushar-2223 Hotel-Management-System home.php A remote SQL injection vulnerability exists in the HTTP POST handler of the tushar-2223 Hotel-Management-System's home.php file. Manipulating the Name or Email parameters allows attackers to execute arbitrary SQL commands. The exploit is publicly available, increasing the risk of active attacks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2553 3. Malicious Chrome Extension Steals 2FA and Analytics from Facebook Business Manager A deceptive Chrome extension posing as a Meta Business Suite productivity tool is actively stealing Two-Factor Authentication (2FA) seeds, one-time codes, and sensitive business analytics from Facebook Business Manager accounts. This exposes users to account takeover risks despite the presence of 2FA protections. Sources: Gbhackers, Therecord https://gbhackers.com/malicious-chrome-extension-exposes-facebook-manager/ 4. Lotus Blossom Hackers Compromise Notepad++ Update Infrastructure for Espionage Between June and December 2025, the state-sponsored Lotus Blossom group breached the official Notepad++ update hosting infrastructure, enabling them to deliver malicious payloads through trusted developer tool updates. This compromise poses significant risks to users by turning a widely used software update channel into an espionage vector. Sources: Cvefeed, Gbhackers https://gbhackers.com/notepad-breached/ 5. Multiple Remote Code Execution and Injection Vulnerabilities Disclosed in Popular Software Several critical and medium severity vulnerabilities have been disclosed affecting multiple software products including LigeroSmart, yued-fe LuLu UI, vichan-devel, Comfast CF-E4, and others. These include remote code execution via command injection, cross-site scripting, and unverified password changes, with some exploits publicly available, increasing the risk of active attacks. Sources: Cvefeed, Gbhackers, Sans https://cvefeed.io/vuln/detail/CVE-2026-2545 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article primarily discloses several newly identified CVEs with technical details, but it does not provide PoC, exploit code, active exploitation evidence, or patch information.

    0001055
    54 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 16, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. Critical Privilege Escalation and Account Takeover Vulnerabilities in JUNG eNet SMART HOME Server Multiple critical vulnerabilities in JUNG eNet SMART HOME server versions 2.2.1 and 2.3.1 allow low-privileged users to escalate privileges, reset passwords of admin accounts without authorization, and exploit default credentials to gain administrative access. These flaws expose smart home environments to unauthorized control and potential compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-26369 3. Suspected Russian APT Deploys CANFAIL Malware Targeting Ukrainian Critical Sectors A newly identified Russia-linked APT group has deployed CANFAIL malware against Ukrainian defense, government, and energy organizations, posing significant risks to critical infrastructure. The attacks highlight ongoing geopolitical cyber threats and potential disruptions to national security and energy operations. Sources: Feedburner, Securityaffairs https://securityaffairs.com/187976/hacking/suspected-russian-hackers-deploy-canfail-malware-against-ukraine.html 4. CISA Alerts on Critical ZLAN ICS Flaws Allowing Full Device Takeover CISA has issued a critical advisory for severe vulnerabilities in ZLAN5143D serial-to-Ethernet device servers used in industrial control systems. These flaws enable attackers to gain full control over affected devices, risking disruption of critical infrastructure operations. Sources: Cvefeed, Gbhackers https://gbhackers.com/cisa-issues-alert-on-zlan-ics-flaws-enabling-full-device-takeover/ 5. Critical Command Injection Vulnerabilities in Comfast CF-N1 V2 Firmware Two remote command injection vulnerabilities (CVE-2026-2534 and CVE-2026-2535) affect Comfast CF-N1 V2 2.6.0.2 via the mbox-config CGI interface. Both exploits have been publicly disclosed and can be leveraged by attackers to execute arbitrary commands remotely. The vendor has not responded to early notifications, increasing the risk of widespread exploitation. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2535 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article announces several newly identified CVEs across automotive, smart‑home, industrial control, and consumer device domains, detailing their technical nature but offering no evidence of exploitation, PoC, or remediation.

    0001034
    54 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-32061 (CVSS:8.8, HIGH) is Awaiting Analysis. The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos..https://nvd.nist.gov/vuln/detail/CVE-2025-32061 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑32061, highlighting its high CVSS score and its location in the Bluetooth stack of an Infotainment ECU, but no further technical or exploit details are provided.

    0000032
    171 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-32061: HIGH] Critical vulnerability identified in Alps Alpine Bluetooth stack on Bosch Infotainment ECU. Lack of boundary validation can lead to remote code execution, affecting Nissan Leaf ZE1.#cve,CVE-2025-32061,#cybersecurity https://cvefind.com/CVE-2025-32061

    Post summary

    A new critical vulnerability (CVE‑2025‑32061) is disclosed, involving boundary validation failure in the Alps Alpine Bluetooth stack on Bosch Infotainment ECU, enabling remote code execution on Nissan Leaf ZE1.

    0000067
    580 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-32061 - High The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of us... https://www.thehackerwire.com/vulnerability/CVE-2025-32061/ https://t.co/e2fcM43xYF

    Post summary

    A high‑severity CVE‑2025‑32061 affecting the Bluetooth stack of Bosch’s infotainment ECU has been disclosed, detailing a boundary validation flaw; however, no PoC, patch, or evidence of active exploitation is provided.

    0000071
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-32061 The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper … https://www.cve.org/CVERecord?id=CVE-2025-32061

    Post summary

    A new Bluetooth stack vulnerability (CVE-2025-32061) affecting Bosch infotainment ECUs has been disclosed with limited technical details available.

    00000287
    56.4K followersView on X

Explore more