CVE-2025-32062Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper layer L2CAP channel. An attacker can leverage this vulnerability to obtain remote code execution on the Infotainment ECU with root privileges. First identified on Nissan Leaf ZE1 manufactured in 2020.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 8 classified signals
  • Peaked 3d ago at 3 mentions (2026-02-15); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-02-15: 3Mentions · 2026-02-16: 1Mentions · 2026-02-17: 3Mentions · 2026-02-20: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 3Technical Details · 2026-02-20: 102-1502-1602-1702-20
Signal classification1 categories
Disclosure
8100.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-153
Disclosure3
2026-02-161
Disclosure1
2026-02-173
Disclosure3
2026-02-201
Disclosure1
Full discourse8 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 17, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. CVE-2026-2553: SQL Injection in tushar-2223 Hotel-Management-System home.php A remote SQL injection vulnerability exists in the HTTP POST handler of the tushar-2223 Hotel-Management-System's home.php file. Manipulating the Name or Email parameters allows attackers to execute arbitrary SQL commands. The exploit is publicly available, increasing the risk of active attacks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2553 3. Malicious Chrome Extension Steals 2FA and Analytics from Facebook Business Manager A deceptive Chrome extension posing as a Meta Business Suite productivity tool is actively stealing Two-Factor Authentication (2FA) seeds, one-time codes, and sensitive business analytics from Facebook Business Manager accounts. This exposes users to account takeover risks despite the presence of 2FA protections. Sources: Gbhackers, Therecord https://gbhackers.com/malicious-chrome-extension-exposes-facebook-manager/ 4. Lotus Blossom Hackers Compromise Notepad++ Update Infrastructure for Espionage Between June and December 2025, the state-sponsored Lotus Blossom group breached the official Notepad++ update hosting infrastructure, enabling them to deliver malicious payloads through trusted developer tool updates. This compromise poses significant risks to users by turning a widely used software update channel into an espionage vector. Sources: Cvefeed, Gbhackers https://gbhackers.com/notepad-breached/ 5. Multiple Remote Code Execution and Injection Vulnerabilities Disclosed in Popular Software Several critical and medium severity vulnerabilities have been disclosed affecting multiple software products including LigeroSmart, yued-fe LuLu UI, vichan-devel, Comfast CF-E4, and others. These include remote code execution via command injection, cross-site scripting, and unverified password changes, with some exploits publicly available, increasing the risk of active attacks. Sources: Cvefeed, Gbhackers, Sans https://cvefeed.io/vuln/detail/CVE-2026-2545 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The post reports newly disclosed vulnerabilities with technical details but lacks evidence of PoC, exploitation tools, active attacks, or patch information.

    0001055
    54 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 16, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. Critical Privilege Escalation and Account Takeover Vulnerabilities in JUNG eNet SMART HOME Server Multiple critical vulnerabilities in JUNG eNet SMART HOME server versions 2.2.1 and 2.3.1 allow low-privileged users to escalate privileges, reset passwords of admin accounts without authorization, and exploit default credentials to gain administrative access. These flaws expose smart home environments to unauthorized control and potential compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-26369 3. Suspected Russian APT Deploys CANFAIL Malware Targeting Ukrainian Critical Sectors A newly identified Russia-linked APT group has deployed CANFAIL malware against Ukrainian defense, government, and energy organizations, posing significant risks to critical infrastructure. The attacks highlight ongoing geopolitical cyber threats and potential disruptions to national security and energy operations. Sources: Feedburner, Securityaffairs https://securityaffairs.com/187976/hacking/suspected-russian-hackers-deploy-canfail-malware-against-ukraine.html 4. CISA Alerts on Critical ZLAN ICS Flaws Allowing Full Device Takeover CISA has issued a critical advisory for severe vulnerabilities in ZLAN5143D serial-to-Ethernet device servers used in industrial control systems. These flaws enable attackers to gain full control over affected devices, risking disruption of critical infrastructure operations. Sources: Cvefeed, Gbhackers https://gbhackers.com/cisa-issues-alert-on-zlan-ics-flaws-enabling-full-device-takeover/ 5. Critical Command Injection Vulnerabilities in Comfast CF-N1 V2 Firmware Two remote command injection vulnerabilities (CVE-2026-2534 and CVE-2026-2535) affect Comfast CF-N1 V2 2.6.0.2 via the mbox-config CGI interface. Both exploits have been publicly disclosed and can be leveraged by attackers to execute arbitrary commands remotely. The vendor has not responded to early notifications, increasing the risk of widespread exploitation. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2535 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article reports newly disclosed vulnerabilities—including stack buffer overflows, privilege escalation, and remote command injection flaws—across various devices, without evidence of active exploitation, patches, or PoC code.

    0001034
    54 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Bosch Infotainment System ECU (CVE-2025-32062) https://vuldb.com/?id.346138

    Post summary

    A severe vulnerability, CVE-2025-32062, has been disclosed for the Bosch Infotainment System ECU. The announcement provides no additional technical details, patches, or evidence of exploitation.

    0001078
    2.1K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-32062 (CVSS:8.8, HIGH) is Awaiting Analysis. The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos..https://nvd.nist.gov/vuln/detail/CVE-2025-32062 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The statement is a brief disclosure of CVE‑2025‑32062, a high‑severity flaw in Alpine’s Bluetooth stack for infotainment ECUs, with limited technical detail and no evidence of exploitation or mitigation.

    0000031
    171 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-32062: HIGH] Critical Bluetooth vulnerability in Alps Alpine stack on Bosch Infotainment ECUs, allows remote code execution on Nissan Leaf ZE1 2020 model due to lack of boundary validation.#cve,CVE-2025-32062,#cybersecurity https://cvefind.com/CVE-2025-32062

    Post summary

    The tweet announces CVE-2025-32062, a high‑severity Bluetooth RCE vulnerability in the Bosch Alpine stack affecting Nissan Leaf ZE1 2020, providing technical details but no PoC, exploit, or patch information.

    0000095
    580 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-32062 - High The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of us... https://www.thehackerwire.com/vulnerability/CVE-2025-32062/ https://t.co/SFNlgVDaTa

    Post summary

    A high‑severity vulnerability (CVE‑2025‑32062) affecting the Bluetooth stack in Bosch infotainment ECUs was disclosed, highlighting a boundary validation flaw, but no PoC, exploit, or patch information was provided.

    0000061
    112 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-32062 Bluetooth Stack Buffer Overflow in Bosch Infotainment ECU Enabling Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-32062

    Post summary

    CVE-2025-32062 is a Bluetooth stack buffer overflow in the Bosch Infotainment ECU that permits remote code execution.

    0000037
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-32062 The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper … https://www.cve.org/CVERecord?id=CVE-2025-32062

    Post summary

    The post references CVE-2025-32062, noting a flaw in the Bluetooth stack of a Bosch Infotainment ECU produced by Alps Alpine, but provides no PoC, patch, or exploitation details.

    00000217
    56.4K followersView on X

Explore more