KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack

CVE Details

Basic Information

Title KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
Type cve
Published 2025-06-13T14:25:50.597Z
Last Seen

Product Information

Vendor KIA
Product Aftermarket Generic Smart Keyless Entry System
Version KIA Ecuador Key Fobs version 2022/2023

CVSS Information

Base Score 9.4 (CRITICAL)
Attack Vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description The KIA-branded Aftermarket Generic Smart Keyless Entry System uses fixed learning codes for locking and unlocking cars, allowing a replay attack. This vulnerability affects key fobs primarily distributed in Ecuador. The manufacturer is currently unknown, and the CVE record will be updated once clarified.
AI Severity Critical
Vendor Unknown
Product Aftermarket Generic Smart Keyless Entry System
Affected Version KIA Ecuador Key Fobs version 2022/2023

Affected Products

  • KIA Aftermarket Generic Smart Keyless Entry System KIA Ecuador Key Fobs version 2022/2023

Additional Information

CVE List
CWE List CWE-307, CWE-294
Bulletin Family

Description

Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack.

Manufacture is unknown at the time of release. CVE Record will be updated once this is clarified.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.