---
id: CVE-2025-69515
title: >-
  An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows
  attackers to force the infotainment system into accepting falsified GPS
  signals as legitimate, resulting in the device reporting an incorrect or
  static location.
summary: >-
  An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows
  attackers to force the infotainment system into accepting falsified GPS
  signals as legitimate, resulting in the device reporting an incorrect or
  static location.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-941
published: '2026-04-07'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69515'
references:
  - url: >-
      https://github.com/thorat-shubham/JXL_Infotainment_CVE-2025-69515/blob/main/README.md
    label: cve@mitre.org
tags:
  - nvd
  - exploit-available
epss: 0.00465
epssPercentile: 0.37639
ingestedAt: '2026-07-25T23:05:57.819Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/thorat-shubham/JXL_Infotainment_CVE-2025-69515'
  checkedAt: '2026-09-26T09:05:36.244Z'
exploitAvailable: true
---

## Overview

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
