PT-2026-52445 · Unknown · Remote Keyless Entry System
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Remote Keyless Entry System (RKES) using 433 MHz key fob FCC ID CWTR53R0 (affected versions not specified)
Description
The system is susceptible to a roll-back attack targeting its rolling-code authentication. An attacker within radio frequency range can record two consecutive lock or unlock transmissions from a legitimate key fob and subsequently replay that pair of transmissions. Replaying the first captured transmission puts the system into a state where the second transmission successfully triggers a lock or unlock operation of the vehicle.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Keyless Entry System