CVE-2026-2539
Unknown
Unknown - Not Provided
Unencrypted RF Protocol in Micca KE700 Enables Authentication Bypass
Publication date: 2026-02-15
Last updated on: 2026-02-15
Assigner: Automotive Security Research Group (ASRG)
Description
Description
The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g., SDR) can capture the random number and counters transmitted in cleartext, which is sensitive information required for authentication.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| micca | auto_electronics_ke700 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |