← Zurück zur CVE-Suche

CVE-2026-49319

ALPS ALPINE CO. Remote Keyless Entry System

Beschreibung

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication. An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).

CVSS 6.5EPSS 0.24%Risiko 0.66
Quelle öffnen
Veröffentlicht
2026-06-25 15:16:37
Betroffene Versionen
unknown
Typ
Festplattenmodell
Vektor
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N