Bluetooth Authentication Weakness in KARR Security Systems by KARR
CVE-2026-18411
7.2HIGH
What is CVE-2026-18411?
The KARR Security System and SWDS dealer-installed automotive anti-theft systems exhibit a significant security flaw due to the use of a shared Bluetooth authentication key across multiple devices. This vulnerability allows attackers within Bluetooth range to exploit the weakness and send unauthorized commands to the vehicle. As a result, unauthorized access to vital vehicle functions, such as unlocking doors or manipulating engine systems, could be achieved. Users should remain vigilant and consider security measures to safeguard against potential exploitation.
Affected Version(s)
DR-100 Versions prior to July 20, 2026
KARR BT Versions prior to July 20, 2026
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, and Nishant Bhaskar of UC San Diego team discovered this vulnerability.
