CVE-2026-18411
Received Received - Intake

Authentication Key Flaw in KARR Security System

Vulnerability report for CVE-2026-18411, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: ICS-CERT

Description

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the KARR Security System and SWDS automotive anti-theft systems using a shared Bluetooth authentication key across devices. An attacker within Bluetooth range can exploit this to send unauthorized commands to a vehicle, potentially unlocking doors or disabling the engine.

Detection Guidance

Detecting this vulnerability requires checking for Bluetooth devices using the shared authentication key. Use Bluetooth scanning tools like hcitool or bluetoothctl to identify devices with weak authentication. Look for devices with default or easily guessable keys. Monitor for unauthorized Bluetooth commands or unusual activity near vehicles equipped with the KARR Security System or SWDS.

Impact Analysis

If you own a vehicle with the affected anti-theft systems, an attacker could gain unauthorized access to your vehicle's functions, such as unlocking doors or immobilizing the engine, without physical access.

Compliance Impact

The vulnerability allows unauthorized access to vehicle functions via Bluetooth, which could lead to data breaches or unauthorized control. This may impact compliance with standards requiring physical or digital access controls, such as GDPR (data protection) or HIPAA (health data security), if vehicle systems process regulated data.

Mitigation Strategies

Immediately update the Bluetooth authentication keys on all affected devices to unique, strong keys. Disable Bluetooth pairing mode when not in use. Ensure vehicles are parked in areas with limited Bluetooth range. Contact the manufacturer for firmware updates addressing this issue. Monitor for suspicious activity and restrict unauthorized access to vehicle functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18411. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart