CVE 6.5 MEDIUM

Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack_CVE-2026-49319

6.5 / 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication.Β 



An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed onΒ a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).

Basic Information

ID CVE-2026-49319
Source ASRG
Published Jun 25, 2026 at 14:11
Modified Jun 25, 2026 at 15:12

Affected Product

Vendor Alps Electric Co., Ltd.
Product Remote Keyless Entry System (RKES) R53R0
Version R53R0
Affected Versions Alps Electric Co., Ltd. Remote Keyless Entry System (RKES) R53R0 R53R0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.