Deep Water research

VW Group Bluetooth Systems Guide

I need to know everything about blutooth protocols of vw group cars. Structure, how to connect, auth, read and hopefully write.

Sep 25, 202665 sources reviewed

Executive Summary

  • VW infotainment Bluetooth is Classic Bluetooth for phone and audio, not diagnostics. Discover systems advertise HFP, A2DP, AVRCP for phone and media [59], with Discover Pro manuals defining A2DP for music and AVRCP for remote control [30]. Diagnostic read/write over Bluetooth uses a separate OBD-II dongle plugged into the OBD port, bridged by Bluetooth to a phone app [11][14].
  • Hardware generations matter. MIB2 is the second-generation Modular Infotainment Box introduced in the early 2010s; MIB3 is the third generation from the late 2010s with more powerful processor, high-resolution touch and CarPlay/Android Auto/Wi-Fi [38]. Attack research specifically names Skoda MIB3 and VW MEB ICAS3 head units [1][5]. Address 5F Information Electronics (J794) is the infotainment module seen in scans [17].
  • Pairing is standard Bluetooth Secure Simple Pairing with VW UI on top. Legacy installs use PIN 0000 or 1234 [28][40]; newer flows show numeric comparison — confirm same code on car and phone, tap Pairing/Yes [6][36][46][50]. Only paired, visible devices connect, and audio is typically one active stream at a time [30][40].
  • Security boundary is the infotainment domain, plus UDS/SFD at the OBD port. Bluetooth BR/EDR evolved legacy → Secure Simple Pairing → Secure Connections with different encryption/authentication/key-generation [2]. PerfektBlue chain (CVE-2024-45431 to CVE-2024-45434) achieved 1-click RCE via BlueSDK after pairing, demonstrated on MEB ICAS3 and MIB3, requiring 5–7 m proximity, ignition on, pairing mode and user approval [1][4][5]. VW states steering, brakes, engine and assistance stay on a separate controller [4][5]. For coding, classic SecurityAccess 0x27 seed-key [31][42] is increasingly gated by SFD/SFD2 online tokens, typically 90-minute unlocks [39][41][44].
  • Recommendation: treat car Bluetooth as untrusted audio/phone transport; do all diagnostic work through a wired or reputable Bluetooth LE/Classic OBD adapter with SFD-aware tooling, expect PIN/numeric-compare pairing, verify AVRCP/HFP versions for steering-wheel and metadata support, and budget for online SFD authorization on MY2020+ cars.

1. VW Group Bluetooth Hardware and System Architecture

1.1 MIB generations and vehicle platforms

MIB2 stands for Modular Infotainment Box 2, described as basic navigation, audio and Bluetooth connectivity over basic Bluetooth and USB [38].

MIB3 stands for Modular Infotainment Box 3, described as enhanced performance, modern UI, plus Apple CarPlay, Android Auto and Wi-Fi [38].

A commonly cited model-year split is 2010–2016 mostly MIB2 and 2017 onward typically MIB3, with upgrade depending on hardware compatibility and sometimes full-unit replacement [38].

The evidence does not provide chipset part numbers, RF front-end details or antenna gains for MIB units. What it does provide is:

  • Functional split: older MIB uses SBC; MIB3 uses SBC plus AAC; ID. Series uses AAC plus aptX, per a VW connectivity guide [40].
  • Attack-research platform labels: Volkswagen MEB ICAS3 and Skoda MIB3 head units, plus Mercedes-Benz NTG6 for comparison [1][5]. Demonstration vehicles named are Volkswagen ID.4 (ICAS3) and Skoda Superb (MIB3) [5].
  • Diagnostic address: retrofitted Discover Pro Gen2 reports as Address 5F: Information Electr. (J794) with e.g. SW 3G0 035 021 B, HW 3G0 035 021, component MU-H-TND-EU H33 0343, and a second unit 3G0 035 025 / MU-H-LNS-US [17]. VCDS labels it 5G0-035-MIB-HGH2.clb with ASAM EV_MUHig4CGen2HBAS, indicating MIB High Gen2 [17]. Scanned vehicle in that thread is MQB platform, chassis AU (5Q0), gateway GW MQB High [17].
  • Discover Media/Pro and second-generation Discover Pro connection options explicitly include USB plus Bluetooth [59].

Gap: no cited source gives MIB/MIB3 Bluetooth SoC vendor, Bluetooth Core version per head-unit SW, transmit power class, or antenna placement beyond the points below. Do not assume a uniform stack across VW, Skoda, SEAT, Audi and Porsche; BlueSDK itself is described as a modifiable framework vendors adapt [1].

1.2 Telephone modules, cradles and antennas

Older architectures used a separate Bluetooth module rather than Bluetooth fully inside the head unit:

  • Under-seat Nokia Bluetooth module paired with RNS300 plus touch adapter is reported [24].
  • Under-seat Bluetooth box talking to RNS310, with Touch adapter pairing to that box and control via RNS310, is reported [54].
  • Cradle adapter 3C0051435PA for RNS300 only adds a Bluetooth link: phone pairs to the docked adapter instead of docking the phone [54].
  • Premium Bluetooth Module OEM 7P6035730D is named as replacement hardware in a Passat pairing thread [24].
  • RNS510 identification is by SW version in photos [55]; RNS510 with VW Music Interface MDI USB/Aux is factory behaviour, with aftermarket USB options such as Yatour also mentioned [55].

Antenna topology evidence is fragmentary but concrete:

  • Two purple connectors on Discover Pro rear, assumed one in from Premium Telephony base plate and one out to sharkfin [17].
  • US car Telematics module over LTE fed by roof sharkfin [17]; e-Golf topology uses rear-window antenna loop with dedicated aerial plugs [17]; premium-telephony fitment changes rear-connector layout; some units have one telephone-antenna connector, reporter's unit has two [17].
  • Modules are described generically as embedded into the vehicle CAN bus to integrate with radios, clusters and steering-wheel buttons, with automotive temperature -40C to 85C and EMI hardening claimed in a buying guide [57]. Treat the temperature and CAN-integration claims as generic module requirements, not a VW datasheet.

VW wiring, fuse, module, coupling-point, relay and earth-point drawings are in the Erwin basic-equipment document, pay-per-time download [17]. One cited price for 1-hour access including printing is EUR 7.00 (≈ GBP 6.02).

Generation / unit What evidence says Connectivity cited
MIB2 / Discover Pro Gen2 (MU-H) Second-gen MIB, early 2010s, standard touch, older software [38]; 5F J794 MU-H examples [17] Basic Bluetooth, USB [38]; BT audio + hands-free [30]
MIB3 / MEB ICAS3 Third-gen, late 2010s, more powerful processor, high-res touch [38]; ICAS3 and MIB3 named in PerfektBlue demos [1][5] CarPlay, Android Auto, Wi-Fi [38]; Bluetooth 5.0+ on up-to-date models [40]
RNS300/RNS310/RNS510 + external BT Separate under-seat / cradle BT box [24][54]; RNS510 SW identification [55] HFP phone, A2DP streaming varies by module/phone compatibility [55]
Premium telephony / rSAP era VW PREMIUM MY2011 adds HFP alongside SAP; Audi/Porsche/SEAT/Skoda PREMIUM SAP lists given [12] SAP/rSAP on Android/Maemo/MeeGo; iOS/Windows Phone use PBAP instead [12]

1.3 Stack vendor

Volkswagen and Skoda entertainment systems are reported to use OpenSynergy BlueSDK [4].

  • Widely adopted automotive Bluetooth implementation [1].
  • Hardware-agnostic, supporting Classic and Low Energy modes and various standard profiles [1].
  • Specifically providing hands-free, voice commands and audio streaming [5].

This explains why one set of CVEs affected multiple brands: flaws in shared L2CAP, RFCOMM and AVRCP code [1][5].

2. Bluetooth Protocol Stack and Supported Profiles

2.1 Classic vs Low Energy in the car

Classic Bluetooth is built for continuous voice and data such as car hands-free and stereo streaming, typically up to 3 Mbps with robust error correction [20].

  • Topology: piconet where a master connects up to 7 active slaves in point-to-point star links, with no standard one-to-many broadcast or mesh [20].
  • Modulation and rate: Basic Rate uses GFSK for 1 Mbps; EDR uses π/4-DQPSK for 2 Mbps and 8-DPSK for 3 Mbps [56][20].
  • Hopping: 1600 hops/s over 79×1-MHz channels [56][20].
Classic Bluetooth modulation rates

Instant data rate by modulation scheme

Classic Bluetooth modulation rates00.751.52.253Mbit/sGFSK (Basic Rate)GFSK (Basic Rate): 1 Mbit/s [56]1π/4-DQPSK (EDR2)π/4-DQPSK (EDR2): 2 Mbit/s [56]28-DPSK (EDR3)8-DPSK (EDR3): 3 Mbit/s [56]3
Data and sources
GFSK (Basic Rate)1 Mbit/s [56]
π/4-DQPSK (EDR2)2 Mbit/s [56]
8-DPSK (EDR3)3 Mbit/s [56]

BLE uses the same 2.4 GHz ISM band but different modulation, allowing coexistence and shared hardware including antenna [15].

  • Channels: 40×2-MHz channels [3][20][56]; stays idle until needing to send and focuses on short exchanges [20].
  • Rate and range: potential rate cited as 1 Mbps with 30-m line-of-sight, in practice tuned to 40–80 Kbps at 2–5 m for power saving [15].
  • Interoperability: Classic-only and BLE-only devices are not directly interoperable; most phones/modules are dual-mode by time-sharing radio, and specs since 4.0 encompass BR/EDR plus LE [20].
  • Audio: LE Audio arrived with 5.2 using LC3 capped near 500 kbps [20].

For VW specifically, one guide states systems use a combination of BLE and Classic, BLE for power-efficient keyless/NFC-pairing type features and Classic for heavier audio transfer [40].

  • Up-to-date models support Bluetooth 5.0+; older firmware without 5.0/5.2 causes phone-compatibility issues; future LE Audio adoption is expected to improve range and latency [40].
  • Newer models are also said to leverage BLE for Phone-as-a-Key and for TPMS/battery-management beyond infotainment [57].

Treat those as guide claims, not VW specifications.

Baseband and link protocols:

  • Baseband defines ACL for bursty data and SCO for stable real-time voice [23]; HFP audio uses synchronous SCO with separate control channel [9].
  • LMP manages link establishment/configuration/release and negotiates encryption/authentication, monitors signal/BER and adjusts power/rate [23].
  • L2CAP multiplexes upper protocols, segments/reassembles large packets and supports QoS [23].
  • RFCOMM emulates RS-232 serial per ETSI 07.10 [12][23][32].
  • SDP lets devices discover peer service types, attributes and access parameters via service records [23]; SDAP describes using SDP to discover services [12].
  • HCI is the host-controller interface expanding compatibility [56], carrying host-to-controller commands and controller-to-host events [3].
  • Chips generally talk to the host via UART, USB, SDIO, I2S or PC Card [32].

BLE stack roles:

  • GAP defines discovery and connections [8]; GAP is mandatory and defines discovery, security, connectivity and topology [15]. GAP underlies all other profiles and defines how two units discover and establish connection [12].
  • GATT manages attribute transfer once connected [8], sitting on ATT [8][20], grouping attributes into characteristics, characteristics into services, services into profiles [8]. A service groups related attributes; a characteristic holds declaration, value and optional descriptors [15][61]. SIG-adopted 16-bit UUIDs embed in base 0000XXXX-0000-1000-8000-00805F9B34FB; custom uses 128-bit [3][61]. Handles are 16-bit 0x0001–0xFFFF [61]. Client reads/writes; server stores [8]; GAP and GATT roles are independent [8][15]. Notifications are unacknowledged; indications require confirmation within 30 s; requests require response/error within 30 s [3][61].
  • No cited source enumerates VW-proprietary GATT services. Generic automotive Android IVI exposes HFP, PBAP, MAP, A2DP, AVRCP as client profiles [13][22][58]; use that only as context, not as VW MIB GATT table.

2.2 Profiles actually used for phone and media

Volkswagen Discover Navigation lists phone/media Bluetooth as (HFP, A2DP *, AVRCP **) [59]. Discover Pro manual likewise supports Bluetooth audio-device connection/playback and hands-free calling plus incoming-mail check when a phone is connected [30].

Profile Role in VW Key technical points from evidence
HFP Hands-Free [9][12] Make/receive calls via car [13][58]; phone is Audio Gateway/Server, car is Car Kit/Client [12]; phone as Gateway, radio as hands-free [48] SCO mono audio, CVSD and mSBC, 8–16 kHz, ~20–30 ms delay; AT commands for control [9]; v1.6 wideband mSBC, v1.7 battery indicator, v1.9 LC3-SWB [12];-basic call answer on MIB1 via HFP but no media/Siri [60]
A2DP Advanced Audio Distribution [9][12] Stereo streaming phone→car [13][22]; high-quality music playback [9] Unidirectional up to 2-ch stereo [12]; relies on AVDTP/GAVDP [12]; mandatory SBC, optional MP2/MP3/AAC/HE-AAC/ATRAC, extensible aptX/LDAC [12]; A2DP plays MP3/AAC mono/stereo [48]
AVRCP Remote Control [9][12] Car controls/browses phone player as controller; playback controls depend on A2DP [13][22] Data channel for control [9]; v1.0 play/pause/stop, v1.3 metadata + player state, v1.4 browsing + Now Playing + absolute volume, v1.5 clarifications, v1.6 folder counts + cover art via BIP over OBEX [12]; radio displays name/artist/album/title from v1.3 [48]; full iOS wheel integration needs AVRCP 1.6+ and HFP 1.7 per guide [60]; Fairphone+Golf VII fix used AVRCP 1.4 + MAP 1.2 [62]; below 1.6 no cover-art media items [62]
PBAP Phone Book Access [9][12] Download contacts/call history to car; show caller name; dial from car display [12]; car requests download, user confirms [48] vCards over data channel [9]; PSE server = phone, PCE client = nav/car [12]; one-way, IVI must initiate; per-device state machine; on disconnect contacts/history deleted [13][22]; iPhone Allow sync, Android allow contacts/history prompts [30]
MAP Message Access [9][12] SMS/email access for hands-free [9]; IVI receives/parses/broadcasts, not stored locally [13][22] SMS/email notifications, download/upload, folder browse [9]; IVI must initiate MAP; dual authorization required [13][22]; mostly automotive hands-free [9][12]; introduced iOS 6, Android 4.4 [12]
SPP Serial Port [12] Virtual serial over RFCOMM; basis for DUN/FAX/HSP/AVRCP [12]; max payload 128 bytes [12] Based on ETSI 07.10 + RFCOMM, emulates RS-232 [12]; up to 128 kb/s, depends on GAP [32]; channel per service found via sdptool SDP [32]
HSP Headset, OPP, SAP/rSAP HSP mono 64 kbps SCO, GSM 07.07 AT subset, now largely obsolete vs HFP [9][12]; OPP pushes contacts, limited count [48]; SAP lets car GSM use phone SIM + car antenna [12] HSP obsolete due to HFP [9]; VW PREMIUM MY2011 HFP fallback for SAP phones, minimal speaker/mic function [12]; Android/Maemo/MeeGo support SAP, iOS/Windows Phone do not [12]

Bluetooth operates at 2.4 GHz ISM [9], tolerant via AFH [9], with range about 10–100 m class-dependent [9].

  • Most common 2.5 mW mode up to about 10 m [56]; in-car pairing guidance says stay under 10 m [35]; devices stay paired around 10 m degrading with obstacles [52].
  • Power classes cited are Class 1 100 mW, Class 2 2.5 mW, Class 3 1 mW [56].
  • Discover Pro manual describes Bluetooth as license-free 2.45 GHz, 1 Mbps, usable within 10 m even with obstacles unlike IrDA [30].
Bluetooth power classes by maximum output

Maximum output power by class

Bluetooth power classes by maximum output0255075100mWClass 1Class 1: 100 mW [56]100Class 2Class 2: 2.5 mW [56]2.5Class 3Class 3: 1 mW [56]1
Data and sources
Class 1100 mW [56]
Class 22.5 mW [56]
Class 31 mW [56]

App-Connect (CarPlay/Android Auto/MirrorLink) is separate from pure Bluetooth audio: it uses USB plus Bluetooth plus WLAN depending on model/year [45].

  • Wireless via CarPlay/Android Auto/MirrorLink after initial We Connect pairing and Bluetooth association [51].
  • First-gen pre-2020 via USB cable; second-gen post-2020 USB-C with wireless for iOS/recent Android, radio link via Bluetooth not cable [53].

Bluetooth itself is described as only handling audio and phone calls in that guide [40].

3. Discovery, Pairing and Connection Establishment

3.1 What the driver sees

Procedures vary by model, grade and nav type [6][36]. Representative flows:

  • T-Cross example: MENU (top-left) → Media (bottom-left) → Settings (bottom-right) → Select BT audio device, then search phone for number shown on nav and tap matching alphanumeric entry [6].
  • PHONE hard key: tap PHONE left of nav, car shows VW BT XXXX, select same name on phone [36].
  • Media/Phone + gear: turn on central display, press Media or Phone beside screen, tap gear bottom-right, select Bluetooth, check Bluetooth, set Visibility to Visible [50].
  • Source select: Media (top-left) → Quelle/Source (bottom-left) → BT-Audio; new device via Neues Gerät suchen / Gerät auswählen → Ergebnisse [46]; audio BT streaming via Media → Sorgente/Source → Audio BT [50].

Car appears to phone as VW Radio, VW Bluetooth or similar [43], or VW BT XXXX [36], or VW Phone [55]. Phone appears on car as connected Bluetooth audio device name [6] or phone/carrier/battery/signal display [30].

Operational notes:

  • Bluetooth ON/OFF, discoverability (searchable/not searchable) and device name are unit settings [30].
  • Multiple devices can be registered but only one audio connection active, must switch [30]; another guide says typically one active Bluetooth connection at a time [40]; Discover Pro Japan manual says up to two Bluetooth phones can be connected, third requires replacing one [30]. Newer MIB3/ID. remember paired devices and auto-reconnect after a drive [40][52].
  • Phone must be within range and discoverable; car must be in search mode [35]; proximity especially important when pairing [52]. Disable in-car hotspot during pairing if public Wi-Fi interferes; USB 3.0 in 2.4 GHz and low-battery power-save disabling Bluetooth are cited as interference causes [52].
  • Basic discovery can succeed both directions (car sees phone, phone sees car) yet profile creation can stall, e.g. MFA left-arrow with old wheel lacking left/right buttons, suspected BAP vs MFA protocol mismatch [24].

3.2 Pairing and authentication ceremonies

Two families appear:

Legacy PIN: enable phone Bluetooth discoverable, car Search for device / Add new device, select phone, enter passcode typically 0000 or 1234 [28]; older pre-2018 VW defaults to PIN 1234 or 0000 [40]. Pre-2.1 legacy pairing requires same PIN on both [56]. If radio asks for Audi PIN or VW radio code, enter before connecting [35].

Secure Simple Pairing numeric comparison shows the same code on both sides:

  • Same code shown both sides, tap Pairing on phone and Yes on car [6].
  • Confirm same password then Yes + Pairing [36].
  • Confirm matching password/code with Ja [46].
  • Code on both displays must match before Abbina/Associa [50].
  • iPhone Allow contacts/favorites/history sync; Android pairing code plus allow contacts/history [30].

Under the hood, SSP uses public-key crypto with Just Works, Numeric Comparison, Passkey Entry and Out-of-Band [56]. VW UI above maps to Numeric Comparison (6-digit compare) or Just Works/PIN fallback. Generic Bluetooth pairing concludes with a link key both sides retain for future auth/encryption [10].

GAP connection management for BLE follows advertiser/central logic: peripheral advertises, central listens and sends CONNECT_IND (legacy) or AUX_CONNECT_REQ (extended) [3].

  • Legacy advertising repeats same payload on primary channels 37/38/39, 31-byte host data; extended up to 1650 bytes with fragmentation [3].
  • Passive scan only receives; active scan sends scan requests [3].
  • Central establishes/modifies connection parameters; peripheral can request change [8].
  • Connection request specifies access address, interval, latency, supervision timeout, channel map [3].
BLE advertising payload maxima

Maximum host advertising data by type

BLE advertising payload maxima0412.58251,237.51,650bytesLegacy advertisingLegacy advertising: 31 bytes [3]31Extended advertisingExtended advertising: 1,650 bytes [3]1,650
Data and sources
Legacy advertising31 bytes [3]
Extended advertising1,650 bytes [3]

For automotive Android context (not VW-specific but illustrative of multi-device head units): HFP max simultaneous defined by MAX_STATE_MACHINES_POSSIBLE/MAXIMUM_CONNECTED_DEVICES in HeadsetClientService; PBAP by MAXIMUM_CONNECTED_DEVICES in PbapClientService; MAP by same in MapClientService; A2DP limit hardcoded to 1 via kDefaultMaxConnectedAudioDevices in btif_av.cc [13][22][58]. CarBluetoothService keeps per-profile priority lists and connectDevices() connects in priority order [13][22][58]. Default phone policy must be disabled via enable_phone_policy false to avoid conflict with automotive policy [13][22].

Troubleshooting patterns reported:

  • iPhone streams only after forget-and-repair; auto-reconnect gives phone-only (Calls) not Calls + audio/sound [55]. Fix on Sharan: delete both sides, cancel car-initiated request, enable car visibility, initiate from phone to VW Phone, confirm code [55].
  • Samsung S10 not retaining audio setting requiring resync each time [55]; Tiguan 2013 RNS510 connected but no Spotify, phone network switched off [55].
  • No track titles on simple block: only Bluetooth-audio shown, no titles, phonebook not read [43]; titles also missing depending on device limits [30]; mixing phone on one device + audio on another can mix audio, use one [30]; some terminals cannot do data while BT audio connected [30]; multiple calling apps (LINE/Skype) can break unit-originated dialing [30]; NTT docomo N-02D fails after password confirm as unsupported [30].

4. Authentication, Encryption and Security Mechanisms

4.1 Bluetooth link security

BR/EDR security evolved in three phases: legacy, Secure Simple Pairing, Secure Connections [2].

Phase Mechanisms (encryption / authentication / key generation)
Legacy E0 / SAFER+ / SAFER+
Secure Simple Pairing E0 / SAFER+ / P-192 ECDH
Secure Connections AES-CCM / HMAC-SHA-256 / P-256 ECDH + HMAC-SHA-256

Key entities: 48-bit BD_ADDR, 128-bit auth key (link key), 8–128-bit encryption key, 128-bit RAND [2].

  • Auth key is static, called link key, base for all transactions; semi-permanent keys may persist in non-volatile memory, temporary keys must not be reused [2].
  • Encryption key derives from auth key during auth, always 128-bit for auth, 1–16 octets for encryption, regenerated each time encryption activates [2].
  • E0 encrypts only payload, resynced per payload from central address + 26 clock bits + Kenc, with plaintext EN_RAND_C; access code/header stay clear [2].
  • AES-CCM follows RFC 3610 with M=4 (4-octet MIC), L=2 [2].
  • Link Manager refreshes E0 keys at least every 2^28 ticks (~23.3 h) and AES-CCM before counter rollover at 2^38 ticks (~2.72 y) [2].

Pairing details:

  • PIN 1–16 octets, default 0x00 one byte if none; two fixed-PIN devices cannot pair [2].

  • Initialization key via E22 from address+PIN+length+IN_RAND, discarded after exchange [2].

  • Legacy auth is 2-move challenge-response with AU_RAND_A and E1 using claimant address to stop reflection; mutual is two opposite runs [2].

  • Secure auth is 4-move mutual with fresh central/peripheral rands and h4/h5 over secret + btdk + both addresses [2].

  • SSP: fresh 128-bit nonce per run anti-replay, commitments then 6-digit compare, abort on mismatch [2].

  • Numeric Comparison limits active MITM to 0.000001 per iteration; key stays secure vs passive eavesdropper if no active attack during pairing [2].

  • Passkey Entry repeats 20 rounds for 20-bit 6-digit key, forbids static passkeys, gradual disclosure limits leakage to ~1 bit (0.000004 vs 0.000001 brute force) [2].

  • OOB needs OOB data present flag; in-band discovery then OOB not supported [2].

  • Devices should fail if both public keys share X unless debug key, and must validate curve (P-192/P-256) [2].

  • P-256 when both support Secure Connections, else P-192 [2].

  • Link key via f2(DHKey, Nc, Np, btlk, BD_ADDR_C, BD_ADDR_P) with 0x62746C6B [2].

  • Auth key via h4/btdk 0x6274646B, confirm h5 yielding SRES_C/SRES_P/ACO [2].

  • AES key via h3/btak 0x6274616B truncated to 128 MSBs [2].

  • Failures: verifier must back off exponentially up to max, decaying after quiet period [2].

  • MIC failure with good CRC counts as auth failure, max three per key+IV, third triggers refresh, fourth before completion disconnects 0x0E [2].

  • Private key should change after every pairing or when S+3F>8 [2].

Known standard-level issues: KNOB (CVE-2019-9506) key-negotiation and BIAS (CVE-2020-10135) impersonation, evaluated on Apple/Broadcom/Cypress/CSR/Google/Intel/Microsoft/Qualcomm with low-cost hardware, standard amended but many devices still vulnerable [37]. A single standard-compliant flaw translates to billions of devices [37].

  • Pairing ends with link key both must retain [10]; confidentiality depends on secure storage [10].

  • Linux BlueZ often plaintext in /var/lib/bluetooth, Android in /data/misc/bluedroid/bt_config.conf plaintext, Windows in HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys [10].

  • Filesystem-permission-only protection is insufficient with storage access [10].

  • Small/proprietary devices vary by maker and need reverse-engineering/firmware review to verify [10]; TPM presence and software knowledge needed to verify [10].

  • No cited source gives VW MIB key-storage path — do not assume Linux/Android paths apply to the head unit.

BLE security adds AES-128 and LE Secure Connections with ECDH [20]; GATT secure transfer needs efficiency trade-offs [8]; channel-sounding control requires encrypted link so devices must be paired [3].

4.2 PerfektBlue: what it proves about VW Bluetooth attack surface

PCA Cyber Security found four BlueSDK flaws [4]. OpenSynergy fixed them September 2024 and distributed to automakers [4].

CVE Issue CVSS 3.1 cited
CVE-2024-45434 Use-After-Free in AVRCP service [1] allowing malicious code execution over Bluetooth [5] 8.0 Critical [1]
CVE-2024-45433 Incorrect function termination in RFCOMM [1]; manipulated data processed despite unusual state, bypassing checks [5] 5.7 Medium [1]
CVE-2024-45432 Function call with incorrect parameter in RFCOMM [1]; wrong-parameter RFCOMM function exploitable [5] 5.7 Medium [1]
CVE-2024-45431 Improper validation of L2CAP channel remote CID [1]; flawed Channel-ID validation, central to data transmission, allowed unauthorized channels [5] 3.5 Low [1]
PerfektBlue CVSS 3.1 scores by CVE

CVSS 3.1 cited scores for the four BlueSDK flaws.

PerfektBlue CVSS 3.1 scores by CVE02468CVSS 3.1CVE-2024-45434 AVRCPCVE-2024-45434 AVRCP: 8 CVSS 3.1 [1]8CVE-2024-45433 RFCOMM…CVE-2024-45433 RFCOMM termination: 5.7 CVSS 3.1 [1]5.7CVE-2024-45432 RFCOMM…CVE-2024-45432 RFCOMM parameter: 5.7 CVSS 3.1 [1]5.7CVE-2024-45431 L2CAP …CVE-2024-45431 L2CAP CID: 3.5 CVSS 3.1 [1]3.5
Data and sources
CVE-2024-45434 AVRCP8 CVSS 3.1 [1]
CVE-2024-45433 RFCOMM termination5.7 CVSS 3.1 [1]
CVE-2024-45432 RFCOMM parameter5.7 CVSS 3.1 [1]
CVE-2024-45431 L2CAP CID3.5 CVSS 3.1 [1]
  • Chained, they give 1-click RCE in BlueSDK device OS allowing manipulation, privilege escalation and lateral movement [1].

  • Demonstrated against Mercedes NTG6, VW MEB ICAS3 and Skoda MIB3 [1].

  • Impact cited: location tracking, microphone audio recording, phonebook access [1]; GPS tracking, eavesdropping, stored contacts [5]; reverse shell over TCP/IP where infotainment connects to attacker for remote command line on tested VW/Skoda [5].

  • Lateral movement to steering/wipers is theorized but not demonstrated [1].

Preconditions narrow exploitability:

  • Pairing with target to appropriate security level is the only requirement in one description [1]; pairing alone sufficient to start 1-click RCE in another [5].
  • Pairing behaviour is implementation-specific: limited/unlimited requests, with/without user interaction, or disabled [1]; on tested devices flaws reachable after pairing, on other BlueSDK builds potentially before pairing depending on profile security level or Just Works SSP [1].
  • Attacker sends pairing request, infotainment shows device wants to connect and asks permission, connection only if user allows [5]; at most 1-click exploitation [1].
  • VW-stated constraints: max 5–7 m distance [4][5]; ignition on [4][5]; infotainment in pairing mode / user actively pairing [4][5]; owner must actively approve [4].
  • Scope: entertainment system only; steering, brakes, engine, driver assistance on separate controllers with own protections cannot be impaired even after success [4][5].

Hygiene cited: reject suspicious pairings, disable Bluetooth when not needed, install latest software [4].

4.3 UDS SecurityAccess, gateways and SFD — why Bluetooth alone does not code the car

Vehicle networks use specialised protocols per latency/cost; CAN/CAN FD have no built-in security and face spoofing/DoS/bus-off [34]. Any connected node can transmit without authentication, so security relies on gateway enforcement, validation and segmentation [34]. Bluetooth, Wi-Fi and NFC are short-range surfaces extending threat within proximity [34]; attackers pivot via infotainment over Bluetooth/Wi-Fi, TCU cellular, OBD-II or cloud APIs toward central gateway [34]. Flat permissive gateways expose safety domains; hardened gateways default-deny only precomputed message/ID/source/dest paths [34]. Secure Elements, machine-to-machine auth, gateway firewalls, message auth, encryption, IDS, secure boot and OTA via secure gateway are layered defences [49].

UDS (ISO 14229) is client-server, tester as client, ECU as server, in practice over OBD SAE J1962 CAN interface [42]. Structure is layered state machine: right session + security level before flash/calibration/routine [31]. Sessions: Default 0x01 read-only DTC, Extended 0x03 calibration, Programming 0x02 most sensitive for flash [31]. Standard flash: 0x10 session → 0x27/0x29 auth → 0x31 pre-check/erase → 0x34 RequestDownload → 0x36 TransferData → 0x37 exit with hash/signature → 0x31 post-check → 0x11 reset [31].

  • 0x27 SecurityAccess is symmetric challenge-response: ECU seed, tester key from shared-secret algorithm, OEM-defined not ISO-standardised [31]. Seed should be TRNG ≥128-bit; hardened pattern truncated HMAC-SHA256 over seed/level/context with per-device HSM key; per-device HKDF with UID stops fleet cascade [31]. Weak history: fixed seeds, XOR/CRC, LFSR seeds; 16-bit seed (65536 values) allows lookup tables; DLL/firmware extraction via JTAG/glitch/side-channel exposed algorithms [31]. Each level needs independent exchange; already-unlocked returns all-zero seed, skip SendKey [31]; dropping session via S3 timeout/reset/session-change loses unlock [31]. Failures signal 0x35 invalidKey, 0x36 exceededAttempts, 0x37 delayNotExpired, typically 3–5 attempts + 10000 ms NvM-persisted delay; RAM-only counters bypassable by ignition cycle (~3 tries/boot) [31].
  • 0x29 Authentication (ISO 14229-1:2020) adds APCE PKI (X.509, ECDSA P-256/P-384, Root→Intermediate→tester/ECU, expiry/CRL/OCSP) and ACR symmetric, optional bidirectional mutual auth + session-key for 0x84 SecuredDataTransmission (AES-GCM) [31]. Unidirectional: 0x00 config → 0x01 tester cert → ECU nonce → 0x03 proof-of-ownership signature; bidirectional 0x02 mutual cert+challenge exchange [31]. 0x29 roles (e.g. OEM_Engineering, AfterSales_Technician) replace numeric 0x01–0x7F levels [31]. 0x27 deprecated in ISO 15765-4 for new designs but remains in ISO 14229-1 and most ECUs [31]. Gateway migration often keeps 0x27 for in-workshop physical, requires 0x29 APCE + DHE for OTA/remote DoIP/Ethernet [31].
  • MQB reality: modules lock out after couple wrong codes [21]; ignition/Terminal 15 must stay on for countdown, no entries even correct during lockout [21]; check IDE00323 Number of invalid keys, ideal 0, tolerate <3 [21]. Contributed codes include 20103 almost every module incl. 65/BB/BC, engine 01 27971/79153/12233, ABS 01138/20103, instruments 17 25327 pre-MY16 vs 47115 post-MY16, steering 44 19249/28183/44595, central electrics 09 31347/20107/42013, gateway 19 20103, aux heater 18 80782, trunk 6D 12345 [21]. Table is work-in-progress, veracity not guaranteed [21]. Central-electrics example: 09 → Security Access 31347 → Adaptation Leuchte16BLK/Leuchte17TFL [11].

SFD (Schutz der FahrzeugDiagnose / Vehicle Diagnostic Protection) replaces Login/SecurityAccess as diagnostic firewall [44][39].

It intercepts tool↔vehicle requests and can block coding/adaptation [39].

Module generates challenge token unique to session; VAG servers generate release token unlocking full access typically 90 minutes [39].

First-gen SFD is system-level (e.g. unlock Parking Brake/ABS for EPB pads); SFD2 requires unlocking CAN Gateway first [39].

SFD2 is VW interpretation of UNECE R155/R156, mainly Europe since 2024 but also outside UNECE, aimed at ADAS/autonomy/updates/cybersecurity; coding/adaptation/updates only when digitally signed factory-authorized, limiting retrofits [44][39].

Even before SFD, firewall required hood open for full access; newer add diagnostic filter blocking access entirely, VCDS workaround may be read-only -R [44].

Gateway measuring values distinguish Filter not active / hood open vs Filter active / SFD protected [44]; Gateway unlock counts down e.g. 89 min, filter odometer counts down from 20 km (≈ 12 mi) [44].

Neither VCDS nor ODIS can permanently disable SFD/SFD2 [44].

SFD workflow with Bluetooth dongles is still OBD-port + online token, not car-Bluetooth pairing:

  • OBDeleven auto-unlock: with auto-unlock on, Long coding/Adaptation/One-Click on locked unit auto-requests SFD token from VW servers, unlocks and writes [41]; auto-detects lock on write attempt and prompts [41]; manual: connect → unit → SFD button → Unlock, stays 90 min, Lock option relocks early [41]. Limits: 100 unlocks/hour, 40 VINs/day, 1000 unlocks/day; notify + wait ~hour when hit [41]. First use needs verified email, name/surname/phone/country + 2FA [41]; free for PRO/ULTIMATE/One-Click users [41].
  • VCDS uses offline unlock tokens for unlock/relock; needs Challenge/Token for Gateway #19 plus each SFD module when filter active [44]; Auto-Scan suffixes SFD/SFD2/-R show protection [44]; SFD covers Audi/Bentley/Bugatti/CUPRA/MAN/SEAT/Skoda/VW/VW Commercial MY2020/2021 all regions [44]; interface must be registered to single natural person with government photo ID stored 30 years [39]; Ross-Tech does not provide tokens, distributors do, some markets excluded [44].
  • SFD does not block reading ID/DTCs/measuring values [44]; most service jobs (reset, DPF regen, pads) work after regular SFD unlock [44].

5. Reading Data over Bluetooth

Important: car infotainment Bluetooth does not expose UDS/KWP or CAN. Reading means: plug a Bluetooth-capable OBD adapter into the 16-pin OBD-II connector near steering wheel [26] (under wheel beneath coin-holder cubby in example [11]), ignition on without necessarily starting [11], pair adapter to phone via Bluetooth, run app/dongle AT/OBD/UDS polling.

5.1 OBD dongles and apps

  • ELM327 adapters allow only predefined protocols/speeds [7]; cannot send >8-byte packets [7]; incompletely support KWP2000 one-byte-header at data-link layer though DAP4CS workaround exists with low rate [7]; some Chinese firmware uses wrong Fast Init TiniL outside ISO 14230-2, though most v1.5 PIC18F2580/25K80 free of bug [7]; pre-v2.1 unsuitable where CAN has Central Gateway and cannot generate CAN ACKs in monitor mode [7]; most claimed v2.1 are actually v1.3 AT set [7]. Bluetooth version recommended over Wi-Fi for lower latency; some Wi-Fi modules disconnect or large delay [7]. Despite limits, can diagnose most modern vehicles [7]; in K-line, large packets needed for injector/parameter coding so unsuitable for those specials, but in CAN packet limit does not affect transfer so specials can be done [7].
  • Carista: EVO Scanner plugs to OBD-II, phone becomes tool [14]; steps: plug + ignition on, enable Bluetooth + open app + account + CONNECT [14]; app connects to scanner via Bluetooth for diagnostics/live/service/customizations [14]; pulls ABS/SRS/Engine/Transmission/TPMS/HVAC codes in seconds [14]; scans Engine/ABS/SRS/Transmission/TPMS/other units [14]; clear codes/reset lights to verify repair [14]; free includes standard OBD-II read/clear + live OBD + emissions readiness [14]; live RPM/fuel trims/O2 [14], coolant/oil temp [14]; supports Audi/Cupra/SEAT/Skoda/VW among many [14]; EVO+Pro turns hidden factory settings on, reaches ECU for infotainment tweaks to security upgrades, handles DPF/EPB/oil/battery registration [14].
  • OBDeleven: app free but requires purchased OBD dongle via Bluetooth [11]; needs Android 4.1+ with Bluetooth + strong internet Wi-Fi/3-4G [11]; no iOS at that time because Apple does not support required Bluetooth traffic [11]; pair in Android settings with 1234 (optional, faster reconnect) [11]; once connected view car details, view/clear faults, with engine running live data from many sensors [11]. NextGen small Bluetooth tool offers diagnostics incl. freeze-frame + live [16].
  • Comparison: both Carista and OBDeleven offer Advanced Diagnostics to every ECU where supported, incl. engine/transmission/ABS/airbags/A-C/steering [16]; both offer freeze-frame snapshot at fault moment [16] and live data [16]; Carista single iOS+Android app, curated live (engine/turbo/A-C/DPF/battery) [16]; OBDeleven raw uncurated all parameters (e.g. RPM/coolant/oil) [16]; Carista supports third-party apps, OBDeleven own apps only [16]; Carista EVO has K-Line, OBDeleven does not [16]; both support SFD Unlock [16]; both offer service tools (service reset, battery, EPB, DPF, fuel prime, throttle adapt) and personalization (lights/mirrors/doors/infotainment/dings/A-C) [16]; OBDeleven adds raw coding, Carista unlimited changes without per-feature charge vs OBDeleven per-activation charge [16].
  • Leaving OBDeleven plugged overnight can flat battery; do not ignore removal alarm [11].

5.2 Protocols polled through the dongle

OBD-II (SAE J1979): standardized protocol to extract DTCs + real-time via connector [26]; tool sends requests, car returns speed/fuel/DTCs [26]; third parties use dongles/loggers for real-time [26]. 11-bit functional 0x7DF asks all OBD ECUs; physical 0x7E0–0x7E7 targets specific; responses 0x7E8–0x7EF, commonly 0x7E8 ECM, 0x7E9 TCM [26]; 29-bit functional 0x18DB33F1, responses 0x18DAF100–0x18DAF1FF typically ...110/...11E [26]. All OBD via ISO-TP (ISO 15765-2) for >8-byte payloads like VIN/DTCs [26]. Example: Mode 0x01 PID 0x0D to 0x7DF, response on 0x7E8 with 0x32 decodes to 50 km/h (≈ 31 mph) [26]. Ten modes; 0x01 current data, others show/clear DTCs/freeze [26]; response mode = request + 0x40 (0x01→0x41) [26]; ~200 PIDs in 0x01 but only subset supported; 0x01 PID 0x00 reports support for 0x01–0x20, with 0x20/0x40/... paging [26]. Polling guidance: prefer physical 0x7E0 to avoid multiple responses; space 300–500 ms or ECUs may stop responding; up to 6 PIDs per frame, ECU returns supported, multi-frame as needed [26]. VIN via Mode 0x09 PID 0x02, first frame length 0x014=20 bytes, mode 0x49 [26]. Stored DTCs via Mode 0x03 no PID, 2 bytes/DTC, multi-frame if >2 DTCs [26]; 2-byte DTC = top 2 bits category + 14 bits 4-digit hex [26]. Connector near wheel, pin 16 battery, pins 6/14 CAN-H/L [26]; since 2008 CAN mandatory US per ISO 15765, 250K/500K, 8-byte frames, max 5-m cable [26]; pre-2008 KWP2000/ISO 9141-2/J1850 VPW/PWM [26]. Many newer cars gateway-block raw OEM CAN, only OBD-II via connector; OEM proprietary CAN otherwise needs reverse-engineering [26]. German proposal to turn off OBD-II while driving to central server noted [26].

UDS (ISO 14229): standardized across makers/lower layers CAN/KWP/Ethernet/LIN [42]; UDSonCAN = ISO 14229-3, DoCAN = ISO 15765-2/ISO-TP [42]. Request starts Service ID + params (often sub-function second byte); success SID+0x40, fail 0x7F [47]. Negative is 7F + rejected SID + NRC; common 0x11 serviceUnsupported, 0x12 subFunctionUnsupported, 0x13 badLength, 0x31 outOfRange, 0x33 securityDenied, 0x7E/0x7F notSupportedInSession [47]. RAMN example IDs 0x7E0/0x7E8 etc plus functional 0x7DF [47]; physical request = response − 8 (0x7EC→0x7E4) [42]; functional 0x7DF cars / 0x18DB33F1 heavy-duty [42]; functional limited to single-frame <7 bytes, silent if cannot process [47]. Multi-frame: First Frame length 8–4095, tester Flow Control, then Consecutive Frames; simplest FC 30 00 00 00 00 00 00 00 [42]; long 0x22 needs active isotprecv to send FC else only First Frame seen [47]. ISO-TP allows up to 4095-byte payloads interpreted as UDS [47]. Examples: 0x22 ReadDataByIdentifier with 2-byte DID 0–65535 no sub-function [42]; WWH-OBD DIDs prefix 0xF4 (speed PID 0x0D → DID 0xF40D returning 50 km/h (≈ 31 mph)) [42]; VIN via 0x22 DID 0xF190 no NODI vs OBD 0x09/0x02 response 0x49+NODI 0x01 vs WWH-OBD 0xF802 [42]; 0x19 DTCs sub 0x02+mask or 0x42 WWH-OBD +3 bytes, format 0x04 SAE J2012 5 bytes/DTC e.g. P203D [42]; RAMN 0x19 01 FF count, 0x19 02 FF list [47]; UDS DTC top 2 bits 00 P/01 C/10 B/11 U + digits + FailureType + status bits testFailed/pending/confirmed [47]; services <0x10 are J1979 (0x01 current, 0x03 DTCs, 0x04 clear, 0x09 info) [47]; 0x01 PID 0x00 4-byte support mask answers 0x41 [47]; notable PIDs 0x0C RPM, 0x0D speed, 0x1F runtime, 0x49 pedal, 0xA6 odometer [47]; 0x03 no args 2 bytes/DTC, 0x07/0x0A aliases [47]; 0x09 PID 0x00 support, 0x02 VIN, 0x0A ECU name [47]. Tester Present 3E 00 → 7E 00, 3E 80 suppresses positive response [47]. Session 0x10: 01 default, 02 programming, 03 extended, 04 safety; change while driving rejected 0x22 [47]. Modern German/EV gateways increasingly block raw CAN but still allow UDS sensor data via OBD [42]; Nissan/Hyundai/VW EVs with limited OBD still respond to UDS there [42]. Security-critical UDS needs seed-key + session + periodic tester-present [42].

KWP2000 (ISO 14230): defines ECU communication [33]; widely adopted by VW/Audi/BMW/Mercedes late-1990s to mid-2010s [33]; one of OBD-II options alongside 9141-2/J1850/CAN [33]. OBD KWP format bits A1A0=11 functional request, 10 physical response [33]; over CAN rides ISO-TP segmenting up to 4095 bytes with flow control [33]. K-Line 1200–10400 baud UART 8N1 + optional L-Line wakeup [33]; over CAN up to 1 Mbit/s [33]; K-Line needs 5-baud/fast init key-byte handshake, CAN needs none [33]. Services: Read DTCs (current/pending/historical SAE 2-byte + condition) [33]; Clear DTCs + freeze [33]; ReadDataByLocal/Common Identifier for RPM/speed/coolant/intake/O2/fuel-trim + hundreds live [33]; Read Freeze Frame snapshot at fault [33]; flash via RequestDownload/Upload + TransferData [33]; 3 Read-DTC sub-functions vs 21 for UDS [33]; needs periodic tester-present or exits after P3; timings P2 max response, P2* with ResponsePending, P3 gap [33].

Tuning-community notes (bench/reverse-engineering, not VW-endorsed):

  • Log via 0x21 readDataByLocalIdentifier or 0x23 readMemoryByAddress if allowed [29].

  • Fastest small RAM is 0x21 with dynamicallyDefinedLocalIdentifier, 4-byte request with 1-byte header [29].

  • ME7 has handlers but no identifiers except ECU ID [29].

  • ME7 generic logger otherwise slow KWP1281, else addresses changing per SW [29].

  • 0x23 max 254 bytes one range (3-byte addr +1 size), 0x21 response max 253 data after SID+ID [29].

  • 10 DDLIs × max 3 entries on ME7 vs ≥17–20 entries on MED9.1 [29].

  • ECUx/ME7Logger writes table to unused RAM via WriteMemoryByAddress redirecting pointer for 67–68 values in one 0x21 [29].

  • 12 samples/s for 67 values at 10400 baud, 14/s for one value [29].

  • Bench 0x23 ~17 Hz one block, 8–9/s two blocks, AccessTiming minimums →50 Hz [29].

  • MED9.1 rejects 0x23, use 0x2C define + 0x21 read [29].

  • Only last DDLI entry >1 byte unless patched [29].

  • EDC17 rejects 0x23 7F 23 11 and address DDLI 7F 2C 11, but 0x35 RequestUpload + 0x36 TransferData can read RAM [29].

  • MED17 only RequestUpload over TP2.0/K, very slow 3 commands/cell [29].

  • 0x23 synchronous so no torn values but too much at high RPM can watchdog-reset (5000 RPM cut example) [29].

  • Some in-car K-line refuses KWP2000 that works on bench, OBD may expose infotainment not management CAN [29].

  • DDLI logging reaches vars missing from VCDS blocks like rl_w/PID at faster rate, MED9.1 ~40/s default TP2.0 [29].

  • ME7.5 0x13/0x18 DTC reads rejected 7F 10/11, while J1979 0x03/0x04 give triples [29].

  • MED9.1 dev session 86 key = seed+0x11170 [29].

  • Baud via 0x10 second param 0x63=56000 widely incl. clusters, up to 124800 rarely [29].

5.3 ELM327 AT commands used with Bluetooth adapters

ELM327 AT set includes:

  • CFC0/CFC1 flow-control off/on, FC SD/SH/SM data/header/mode [19].

  • CAF0/CAF1 auto-format [19].

  • AL allow >7-byte [19].

  • H0/H1 headers off/on [19].

  • SP h / SP 00 auto / TP h / TP Ah set/try protocol [19].

  • SH xx yy zz / yzz set header [19].

  • ST hh timeout hh×4 ms [19].

  • AT0/AT1/AT2 adaptive timing [19].

  • MA/MR/MT monitor all/receiver/transmitter [19].

  • DP/DPN describe protocol [19].

  • R0/R1/AR responses [19].

  • CF/CM/CRA ID filter/mask/receive addr [19].

  • TA/RA/SR tester/receive addr [19].

  • FI/SI fast/slow init [19].

  • IB 10/96/48 10400/9600/4800 baud + IIA slow-init addr [19].

  • SW/WM wakeup interval/message [19].

  • KW/KW0/KW1 key words [19].

  • NL/D0/D1/V0/V1 length/DLC/variable DLC [19].

  • BI/BD/PC/SS bypass init/dump/close/search order [19].

  • CEA/CP/RTR/CSM/PB extended addr/priority/remote/silent/Protocol B [19].

  • Z/WS/D reset/warm/defaults [19].

  • E0/E1/L0/L1/M0/M1 echo/linefeed/memory [19].

  • RV/CV voltage read/calibrate [19].

  • LP low power [19].

  • BRD/BRT/SD/RD baud divisor/handshake/store/read [19].

  • PP/PPS programmable params summary [19].

6. Writing, Coding and Adaptation over Bluetooth

6.1 What can be written

Via OBD-dongle Bluetooth, tools expose:

  • Long coding: e.g. Engine Control Module → Coding → long-coding toggle on → Byte 9 → untick bit 2 → tick to save for exhaust flaps [11]; procedure notes start in race/sport, engine off then ignition on without start or flaps code closed; verify by airflow at outer exhausts [11].
  • Adaptation: e.g. 09-Central Electrics → Security Access 31347 → Adaptation → Leuchte16BLK / Leuchte17TFL for pace-car lights; majority of central-electrics mods same method/code [11].
  • OBDeleven Pro vs Apps: Pro activation via Settings→Theme→Pro toggle + code [11]; Pro shows coding icon bottom-right of scan to open control units for VCDS-style tweaks [11]; Pro shows every setting + log to revert, Apps hide exact changes and need same App to revert [11]; basic without Pro only pre-configured credit-costing Apps [11].
  • Carista/OBDeleven customizations: lights/mirrors/doors/infotainment/dings/A-C [16]; OBDeleven raw coding in addition to presets [16].

SFD-gated writes need token first (Section 4.3). OBDeleven auto-detects lock on Long coding/Adaptation/One-Click write and prompts for SFD unlock [41]; manual unlock 90 min [41]. VCDS needs Challenge/Token for Gateway #19 + each module when filter active [44].

RAM examples show deeper writes exist but are risky/undocumented:

  • 0x2E WriteDataByIdentifier can write 17-char VIN to 0xF190 after 10 02 programming session, persisting in flash [47].

  • 0x3D WriteMemoryByAddress only RAM and only after programming + 0x27 unlock, can crash ECU [47].

  • KWP flash via RequestDownload/Upload/TransferData [33].

  • UDS flash sequence with 0x34/0x36/0x37 gated by DcmDspServiceSecurityLevelRef/SessionRef [31].

  • Bootloader HMAC ~4–8 KB vs PKI ECDSA 20–50+ KB, ECDSA 500+ ms on M0+ vs <50 ms on M4F/M33 with crypto [31].

6.2 Limits, risks and tool workflow

Practical workflow supported by evidence:

  1. Plug Bluetooth dongle to OBD, ignition on, pair dongle (not car hands-free) to phone — e.g. OBDeleven 1234 in Android Bluetooth settings [11]; Carista CONNECT in app [14].
  2. Scan, record stock values, keep internet for SFD/token and Pro features [11][41].
  3. For SFD cars, unlock Gateway then target module; respect 90-minute window and rate limits (100/hour, 40 VINs/day, 1000/day) [41][44];Gateway countdown and 20 km (≈ 12 mi) filter odometer relock automatically [44].
  4. Write one change at a time; use Pro/raw coding log to revert [11]; Apps users must keep same App to revert [11].
  5. Verify: fault read/clear, live data (RPM/coolant/oil [16]), freeze-frame [16]; exhaust-flap airflow check example [11].

Risks explicitly cited:

  • Wrong SecurityAccess codes lock module after couple tries, countdown needs Terminal 15 on [21].
  • SFD2 only allows factory-authorized signed coding/adaptation/updates; most retrofits/enables blocked [44]; SFD coding only where required for service/maintenance on SFD2 [39]; stealing-by-key-coding is the threat model [39].
  • K-line large-packet limits block injector/parameter coding on ELM327 [7]; CAN mode not affected [7]; CAN ACK/monitor limits pre-v2.1 [7].
  • RAM writes can crash ECU; excessive ReadMemoryByAddress at high RPM can watchdog-reset [29][47].
  • Bluetooth coexistence: phone+audio split across devices mixes audio [30]; phone power-save disables Bluetooth [52]; in-car hotspot/USB 3.0 interfere [52].
  • Cost of getting module wrong: audio-shop/VAG Parts advice of new module for iPhone streaming at EUR 400–500 (≈ GBP 340–430) in a 2020 report, vs used modules around EUR 100 (≈ GBP 86) and warning newest-iPhone module hard second-hand [55]; failed MIB2 BT module diagnosed as 00123 – Bluetooth Interface: No Signal, OEM part 5G0 035 730 C at USD 320–490 (≈ GBP 240–370) replacement [60]. Use these only as dated benchmarks, not current VW pricing.
  • Third-party MIB2 firmware root may break Bluetooth stack permanently losing iOS button response and voids warranty [60]; hacked MIB2 shows B2000/B2012/B201A checksum/dataset/version faults and U1101 Component Protection Active with SWaP invalid on VIN mismatch after combining EU/US units [17].

Limitations / Open Questions

  • No VW-published Bluetooth profile/COD/GATT table was found in evidence. Supported profiles are inferred from Discover specs (HFP/A2DP/AVRCP [59]), manuals (A2DP/AVRCP [30], PBAP/MAP prompts [30]) and guides (codecs [40], AVRCP/HFP versions [60][62]). Exact Bluetooth Core version, codec negotiation, multi-point behaviour and BLE GATT services per MIB SW train remain unknown.
  • Chipset, power, antenna specs missing. No source gives SoC, TX power, antenna gain/placement for MIB2/MIB3/ICAS3 beyond purple/sharkfin/rear-window observations [17] and generic -40C to 85C claim [57].
  • SecurityAccess and SFD codes are community-contributed. MQB table is explicitly work-in-progress with unverified veracity [21]; SFD token flows change with VW backend and UNECE rollout [39][44]. Limits (90 min, 100/hour etc.) are OBDeleven/VCDS reports [41][44], not VW normative text.
  • KWP/UDS tuning details are bench/community. ME7/MED9/EDC17 DDLI/RequestUpload tricks, baud changes and seed+key examples [29][47] are not VW procedures and vary per ECU SW version.
  • PerfektBlue preconditions are vendor-specific. Reachable before vs after pairing depends on BlueSDK profile security/Just Works implementation [1]; distance/ignition/pairing-mode constraints are VW statements reported second-hand [4][5]; fix status (Sept 2024 [4]) needs VIN-specific update confirmation.
  • Tool comparisons are marketing-adjacent. Carista vs OBDeleven claims (curated vs raw live, K-Line, third-party apps, per-feature charging [16]) and Carista Official VW Group Partner label [14] should be validated against current app/firmware and SFD support before purchase.

Currency equivalents are approximate, using reference rates dated 24 September 2026. They do not adjust for local prices, taxes, or purchasing power.

Sources

[1] PerfektBlue Bluetooth attack allows hacking infotainment systems of Mercedes, Volkswagen, and Skoda — https://securityaffairs.com/179789/hacking/perfektblue-bluetooth-attack-allows-hacking-infotainment-systems-of-mercedes-volkswagen-and-skoda.html · professional [2] Part H Security Specification — https://www.bluetooth.com/wp-content/uploads/Files/Specification/HTML/Core-54/out/en/br-edr-controller/security-specification.html · professional [3] 蓝牙™ 入门指南 |蓝牙™ 官网 — https://www.bluetooth.com/zh-cn/bluetooth-le-primer/ · professional [4] Mercedes, VW, Skoda: Bluetooth-Sicherheitslücke gefährdet Millionen Autos — https://www.t-online.de/mobilitaet/aktuelles/id_100816766/mercedes-vw-skoda-bluetooth-sicherheitsluecke-gefaehrdet-millionen-autos.html · professional [5] Millionen Fahrzeuge anfällig für Bluetooth-Hack — https://www.security-insider.de/bluetooth-sicherheitsluecken-infotainmentsysteme-mercedes-vw-skoda-a-b9b7a07d69f6185c2e9c3144b8a024d7/ · professional [6] Bluetoothの接続方法📲 — https://www.vw-okayama.com/staffblog/2023/09/02/9825/ · general [7] ELM327 diagnostic adapter — https://dap4cs.com/elm327 · general [8] How GAP And GATT Work — Bluetooth Low Energy Basics – Punch Through — https://punchthrough.com/how-gap-and-gatt-work/ · general [9] Bluetooth Profiles: HFP, HSP, A2DP, AVRCP, PBAP, MAP — https://www.rfwireless-world.com/terminology/bluetooth-profiles-hfp-hsp-a2dp-avrcp-pbap-map · general [10] BSAM-PA-10 — https://www.tarlogic.com/bsam/controls/storage-bluetooth-link-keys/ · general [11] OBD Eleven - The Basics — https://www.vwroc.com/forums/topic/17466-obd-eleven-the-basics/ · general [12] List of Bluetooth profiles — https://en.wikipedia.org/wiki/List_of_Bluetooth_profiles · general [13] ব্লুটুথ — https://source.android.com/docs/automotive/ivi_connectivity?hl=bn · general [14] Car diagnostics and coding made simple | Carista OBD2 & App — https://carista.com/ · general [15] What is BLE, and How Do its Related GAP and GATT Profiles Work? — https://www.cardinalpeak.com/blog/what-is-ble-and-how-do-its-related-gap-and-gatt-profiles-work · general [16] Carista vs. OBDeleven: Simplifying Your Choice — https://carista.com/blogs/news/carista-vs-obdeleven-simplifying-your-choice · general [17] Discover media/Pro gen 2 — https://forums.ross-tech.com/index.php?threads/5739/ · general [19] ELM327 AT Commands — https://cdn.sparkfun.com/assets/4/e/5/0/2/ELM327_AT_Commands.pdf · general [20] Bluetooth Low Energy vs. Bluetooth Classic: What's the Difference? — https://www.ezurio.com/resources/blog/bluetooth-low-energy-vs-bluetooth-classic-what-s-the-difference?srsltid=AU7gw4Ul4OaPn62feybnRTuldwbe2QegUZ2XrXgsjpCohI6hpnaOxO_P · general [21] MQB platform - Security Codes - work in progress — https://forums.ross-tech.com/index.php?threads/19270/ · general [22] 蓝牙 — https://source.android.com/docs/automotive/ivi_connectivity?hl=zh-cn · general [23] 蓝牙协议全解析:一文蓝牙协议全了解 - 深圳市智兴微科技有限公司 — https://www.wlsiot.com/news/html/?3333.html · general [24] MFA & BT Module verbinding — https://forum.vwpassat.nl/index.php?/topic/46034-mfa-bt-module-verbinding/ · general [26] OBD2 Explained - A Simple Intro [2026] — https://www.csselectronics.com/pages/obd2-explained-simple-intro · general [28] كيفية توصيل الهاتف بلوتوث في سيارة فولكس فاجن — https://www.bitauto.com/ask/10003803760/ · general [29] Print Page - Logging with KWP-2000 protocol — http://nefariousmotorsports.com/forum/index.php?action=printpage;topic=271.0 · general [30] — https://www.volkswagen.co.jp/idhub/content/dam/onehub_pkw/importers/jp/pc/after_service/afterservice_3/about-your-car/customer-information/user-guide/DiscoverPro_9_2_web.pdf · general [31] UDS Security Access vs Authentication: What's the Difference? — https://simmasoftware.com/uds-security-access-authentication/ · general [32] [蓝牙] 1、蓝牙核心技术了解(蓝牙协议、架构、硬件和软件笔记) — https://www.cnblogs.com/zjutlitao/p/4742428.html · general [33] KWP2000 Protocol Stack: The Complete Guide to Automotive Diagnostic Communication — https://simmasoftware.com/kwp2000-protocol-stack/ · general [34] Automotive Network Security: Threats, Standards, and Solutions for Connected Vehicle Safety — https://www.embitel.com/automotive-insights/what-is-automotive-network-security · general [35] Je n'arrive pas à connecter mon téléphone à ma voiture — https://www.code-autoradio.com/actus-auto/connecter-telephone-voiture/?srsltid=AU7gw4VFcAHqUVfDH2DKTlPzs3fJKgr8jVvnYz9K1mA1p6Yjyx32ckCK · general [36] フォルクスワーゲン Bluetoothの接続方法【電話の取り方も】 — https://www.vw-kobehigashi.com/staffblog/2020/04/13/%E3%83%95%E3%82%A9%E3%83%AB%E3%82%AF%E3%82%B9%E3%83%AF%E3%83%BC%E3%82%B2%E3%83%B3-bluetooth%E3%81%AE%E6%8E%A5%E7%B6%9A%E6%96%B9%E6%B3%95%E3%80%90%E9%9B%BB%E8%A9%B1%E3%81%AE%E5%8F%96%E3%82%8A%E6%96%B9/ · general [37] BIAS and KNOB attacks against Bluetooth BR/EDR/LE | Daniele Antonioli — https://francozappa.github.io/talk/bias-and-knob-attacks-against-bluetooth-br/edr/le/ · general [38] Understanding the Differences Between MIB2 and MIB3: A Comprehensive Guide for Car Multimedia Players — https://www.aliexpress.com/s/wiki-ssr/article/mib2-vs-mib-3 · general [39] VCDS: SFD Diagnostic Firewall - Help Me! :: Gendan Automotive Products — https://m.gendan.co.uk/help/6-VCDS:-SFD-Diagnostic-Firewall/ · general [40] The Definitive Guide: How to Connect Volkswagen Bluetooth Without Frustration — https://hub.stellantis.com/article/the-definitive-guide-how-to-connect-volkswagen-bluetooth-without-frustration · general [41] SFD capability now added to OBD Eleven app — https://www.vwroc.com/forums/topic/40501-sfd-capability-now-added-to-obd-eleven-app/page/2/ · general [42] UDS Explained - A Simple Intro (Unified Diagnostic Services) — https://www.csselectronics.com/pages/uds-protocol-tutorial-unified-diagnostic-services · general [43] Мужики, всех с наступившим! Под сиденьем вот такой модуль блютуз (на фото номер). Магнитола вот такая... — https://volkswagen-org.ru/threads/muzhiki-vsex-s-nastupivshim-pod-sidenem-vot-takoj-modul-bljutuz-na-foto-nomer-magnitola-vot-takaja-foto-prilagaju-kak-vrubit-i-polzovat-bljutuz.98868/ · general [44] SFD - Ross-Tech Wiki — https://wiki.ross-tech.com/wiki/index.php/SFD · general [45] Alles, was du über App Connect wissen musst: Die Verbindung zwischen — https://autotimmer.shop/Alles-was-du-ueber-App-Connect-wissen-musst-Die-Verbindung-zwischen-deinem-VW-und-deinem-Smartphone · general [46] Anleitung: VW mit Handy über Bluetooth verbinden | Autohaus E. Röll — https://www.autohaus-roell.de/anleitung-vw-mit-handy-ueber-bluetooth-verbinden/ · general [47] Interacting with UDS — RAMN 1.0.0 documentation — https://ramn.readthedocs.io/en/latest/userguide/diag_tutorial.html · general [48] Ein Leitfaden zur Bluetooth-Technologie in Autos CAR-TRONIC — https://car-tronic.pl/de/ein-leitfaden-zur-bluetooth-technologie-in-ihrem-auto/ · general [49] Andy Birnie, Timo van Roermund BU Automotive ... — https://www.nxp.com/docs/en/white-paper/MULTI-LAYER-VEHICLE-SECURITY-WP.pdf · general [50] Come attivare Bluetooth in auto — https://www.aranzulla.it/come-attivare-bluetooth-in-auto-1287074.html · general [51] Come funziona app connect Volkswagen – guida pratica all’utilizzo - Sva Group — https://www.sva-group.it/novita-volkswagen-nuovo-e-usato/come-funziona-app-connect-volkswagen-ravenna-forli-cesena · general [52] Bluetooth® auto: cos’è, a cosa serve e come attivarlo — https://blog.fratelligiacomel.it/bluetooth-auto · general [53] Volkswagen APP Connect – Cos’è, attivazione e come funziona — https://www.rossiniauto.it/blog-informativo-volkswagen/volkswagen-app-connect-cos-e-attivazione-come-funziona/ · general [54] Bluetooth adapter Volkswagen - Mobiliteit — https://gathering.tweakers.net/forum/list_messages/1486290 · general [55] Help! Geen audio(muziek) via Bluetooth — https://www.vwforum.nl/viewtopic.php?t=205689&start=15 · general [56] Bluetooth — https://id.wikipedia.org/wiki/Bluetooth · general [57] How to Choose VW Bluetooth Module: Buying Guide & Key Features — https://carinterior.alibaba.com/buyingguides/how-to-choose-vw-bluetooth-module · general [58] Bluetooth — https://source.android.com/docs/automotive/ivi_connectivity?hl=ru · general [59] Volkswagen Navigation | Advanced Guidance | VW Ireland — https://www.volkswagen.ie/en/owners-and-services/radio-and-navigation/our-discover-navigation-systems.html · general [60] MK7 Steering Wheel Buttons Work with iOS — If MIB2+ & Updated — https://carinterior.alibaba.com/tips/mk7-steering-wheel-buttons-ios · general [61] Bluetooth GATT: Designing Custom Services and Characteristics — https://novelbits.io/bluetooth-gatt-services-characteristics/ · general [62] Bluetooth car connection - information not properly display on car when playing music — https://forum.fairphone.com/t/bluetooth-car-connection-information-not-properly-display-on-car-when-playing-music/86910?page=2 · general

Source quality: 5 professional, 54 general.

Verification

  • Infotainment vs diagnostic transport conflated: no evidence that car Bluetooth exposes UDS/KWP2000/CAN; all read/write examples require separate Bluetooth OBD dongle in 16-pin OBD-II port plus app, not car HFP/A2DP link.
  • MIB2/MIB3/MEB ICAS3 hardware architecture unsupported: generation definitions, 2010-2016 vs 2017+ split, processor/display claims, SBC/AAC/aptX codec split, Bluetooth 5.0+, CarPlay/Android Auto/Wi-Fi via Bluetooth, and Address 5F J794 examples come from AliExpress wiki, connectivity guides and forum scans, not VW datasheet; no SoC vendor, Core version, power class, antenna gain/placement.
  • BlueSDK as universal VW Group stack overgeneralized: claim that VW/Skoda/Audi/SEAT/Porsche all use OpenSynergy BlueSDK and share L2CAP/RFCOMM/AVRCP flaws is based on secondary press about PerfektBlue, with report itself noting vendors adapt framework.
  • Profile table extrapolated: only Discover spec HFP/A2DP/AVRCP is VW-sourced; PBAP/MAP prompts, SPP 128-byte/128kbps, HSP 64kbps, OPP, SAP/rSAP Android vs iOS, AVRCP 1.3/1.4/1.6 cover-art/browsing, HFP 1.6/1.7/1.9 mSBC/LC3, A2DP codec negotiation and two-phone/multi-point behaviour inferred from Wikipedia and generic Android IVI HeadsetClient/Pbap/Map/A2DP limits, not per-MIB SW train verification.
  • Discovery/pairing/auth ceremonies lack VW normative source: legacy PIN 0000/1234, numeric-comparison flows, VW BT XXXX/VW Radio/VW Phone names, visibility settings, one-audio-stream vs two-phone rules, 10m range, coexistence/interference fixes are dealer blogs and manuals anecdotes; SSP Just Works/Numeric Comparison/Passkey/OOB mapping and GAP advertiser/CONNECT_IND details are generic spec, not VW implementation.
  • Bluetooth link-key storage unknown for MIB: generic Linux BlueZ / Android bt_config.conf / Windows registry plaintext discussion does not give VW head-unit path; report correctly says do not assume but still presents filesystem-permission risk as VW-relevant.
  • PerfektBlue CVE-2024-45431 to 45434 chain has no supporting evidence cards: CVSS 8.0/5.7/5.7/3.5, L2CAP/RFCOMM/AVRCP root causes, 1-click RCE, ID.4 ICAS3/Superb MIB3/NTG6 demos, location/mic/phonebook/reverse-shell impact, and 5-7m/ignition-on/pairing-mode/user-approval constraints are second-hand vendor/press claims; before-vs-after pairing reachability depends on implementation; lateral to steering/brakes theorized not demonstrated; Sept 2024 fix needs VIN-specific confirmation.
  • UDS 0x27 seed-key, 0x29 APCE/ACR PKI, sessions 0x01/0x02/0x03, flash sequence 0x10/0x27/0x31/0x34/0x36/0x37/0x11, gateway firewall/segmentation, SFD/SFD2 90-minute tokens, 100/hour 40 VINs/day 1000/day limits, Gateway 89-min countdown and 20km filter odometer, hood-open filter, VCDS -R workaround are community tutorials and tool-vendor wikis; MQB Security Codes table explicitly work-in-progress unverified; not VW normative and backend/UNECE-R155/R156 dependent.
  • KWP2000/ME7/MED9/MED17/EDC17 logging claims are bench/community reverse-engineering, not VW procedures: 0x21/0x23/0x2C/0x35/0x36 DDLIs, 254-byte/253-byte limits, 12-50Hz rates, 56000-124800 baud, seed+0x11170, watchdog-reset risk vary per ECU SW and in-car vs bench K-line.
  • OBD-II/UDS polling details are generic tutorials not VW-validated: 0x7DF/0x7E0-0x7E7/0x7E8-0x7EF, 29-bit 0x18DB33F1, ISO-TP 4095-byte, Mode 0x01 PID 0x00/0x0C/0x0D/0x1F/0x49/0xA6, Mode 0x03/0x09 VIN 0xF190, UDS 0x22 DID 0xF40D/0xF802, 0x19 DTC format, Tester Present 0x3E, ELM327 AT set; applicability limited by report's own note that newer VW gateways block raw OEM CAN.