Junglewise Threat Intelligence

CVE-2025-55618: Hyundai Navigation App HTML injection in profile name field

CVE-2025-55618 · Severity: high · CVSS 7.3 · Published 2025-08-27

Executive brief

A security vulnerability exists in the navigation software used in certain Hyundai vehicles. An attacker with access to the vehicle's infotainment system can input malicious code into the user profile name field. While the impact is currently limited by character restrictions, this could potentially be used to alter the display of the navigation screen or interfere with the system's normal operation.

Technical details

A Cross-Site Scripting (XSS) / HTML Injection vulnerability exists in the Hyundai Navigation App (version STD5W.EUR.HMC.230516.afa908d) due to improper neutralization of input in the profile name field. An attacker can navigate to Settings > Profile and input HTML tags (e.g., <h1>) which are subsequently rendered by the application UI. While the field has a 14-character limit that currently hinders complex XSS attacks, the rendering of script tags has been observed to affect UI visibility. The attack requires local interaction with the infotainment system to modify the profile settings.

Affected products

  • Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d

Timeline

  • 2025-08-27: disclosed: Initial disclosure and NVD publication

References