Description
The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.
Published: 2026-08-05
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Acrisure KARR BT and DR-100 systems stems from the use of a hard‑coded, shared Bluetooth authentication key. This weakness allows an attacker within Bluetooth range to authenticate to the vehicle’s anti-theft system and send commands that can unlock doors or trigger engine immobilization. The flaw is a classic example of CWE-321, a weak cryptographic key, and its impact is the potential for remote exploitation of critical vehicle functions.

Affected Systems

All vehicles equipped with the Acrisure KARR Security System or SWDS dealer‑installed anti‑theft devices that share the same Bluetooth authentication key are affected. Both the KARR BT and DR‑100 product lines issued before July 20, 2026 are impacted. No specific firmware versions were listed in the advisory, so all versions prior to the July 20 update should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity with some impact on confidentiality, integrity, and availability. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is local, requiring the attacker to be within Bluetooth range. Once inside range, the attacker can exploit the key reuse to gain unauthorized access to vehicle functions. The lack of a publicly known exploit does not reduce the risk because the weakness is inherent in the device design and can be leveraged with standard Bluetooth tools.

Generated by OpenCVE AI on August 5, 2026 at 21:22 UTC.

Remediation

Vendor Solution

Acrisure Protection Group released a firmware update on July 20, 2026, to address this vulnerability. They recommend that affected users should follow the directions found here: https://www.karrsecurity.com/karr-security-firmware-update-instructions.


OpenCVE Recommended Actions

  • Update all Acrisure KARR BT and DR-100 devices to the firmware released on July 20, 2026 by following the instructions at https://www.karrsecurity.com/karr-security-firmware-update-instructions
  • If a firmware update cannot be applied immediately, limit the device’s Bluetooth exposure—disable Bluetooth when not in use or physically isolate the vehicle from other Bluetooth devices in the environment
  • Monitor vehicle control logs and security alerts for anomalous remote command activity and consider implementing network segmentation to prevent unauthorized communication with the vehicle’s anti‑theft system

Generated by OpenCVE AI on August 5, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization.
Title Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-05T20:13:13.067Z

Reserved: 2026-07-30T17:01:44.405Z

Link: CVE-2026-18411

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T21:30:16Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key