Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cpv-8qgx-f9fv

Опубликовано: 23 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmission, allowing for complete unauthorized vehicle operation via a replay attack.

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmission, allowing for complete unauthorized vehicle operation via a replay attack.

EPSS

Процентиль: 20%
0.00275
Низкий

7.3 High

CVSS3

Дефекты

CWE-1390

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmission, allowing for complete unauthorized vehicle operation via a replay attack.

EPSS

Процентиль: 20%
0.00275
Низкий

7.3 High

CVSS3

Дефекты

CWE-1390