CVE-2025-61081
Authentication Key Brute Force in BYD Atto3
Publication date: 2026-05-19
Last updated on: 2026-05-19
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-307 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
In the BYD Atto3 vehicle, there is a vulnerability where an attacker can use a brute force attack to obtain an authentication key that is permanently available.
This authentication key allows the attacker to access and flash the Electronic Parking Brake (EPB) and Supplemental Restoration System (SRS) related Electronic Control Units (ECUs).
How can this vulnerability impact me? :
An attacker who obtains the authentication key can potentially manipulate critical vehicle systems such as the Electronic Parking Brake and Supplemental Restoration System.
This could lead to unauthorized control or modification of these safety-related systems, potentially compromising vehicle safety and security.