The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-29238 | The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 14 Oct 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Positron
Positron px360bt Positron px360bt Firmware |
|
CPEs | cpe:2.3:h:positron:px360bt:8200101542:*:*:*:*:*:*:* cpe:2.3:o:positron:px360bt_firmware:rev8:*:*:*:*:*:*:* |
|
Vendors & Products |
Positron
Positron px360bt Positron px360bt Firmware |
Mon, 15 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-294 | |
Metrics |
cvssV3_1
|
Mon, 15 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-15T20:38:00.539Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56448

Updated: 2025-09-15T20:37:33.627Z

Status : Analyzed
Published: 2025-09-15T20:15:38.127
Modified: 2025-10-14T19:33:01.220
Link: CVE-2025-56448

No data.

No data.