PT-2025-25420 · Unknown · Kia-Branded Aftermarket Generic Smart Keyless Entry System

·

CVE-2025-6029

·

Published

2025-06-13

·

Updated

2025-07-25

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N
Name of the Vulnerable Software and Affected Versions KIA-branded Aftermarket Generic Smart Keyless Entry System versions 2022 through 2025
Description The issue is related to the use of fixed learning codes in the Key Fob Transmitter, which allows a replay attack. This affects KIA vehicles in Ecuador, primarily those using outdated key fobs with vulnerable chips. Attackers can exploit this to unlock vehicles remotely. The estimated number of affected devices is not specified.
Recommendations For KIA-branded Aftermarket Generic Smart Keyless Entry System versions 2022 through 2025, consider disabling the keyless entry feature until a patch is available. Restrict access to the key fob transmitter to minimize the risk of exploitation. Avoid using the vulnerable chips HS2240 and EV1527 in the key fobs until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6029

Affected Products

Kia-Branded Aftermarket Generic Smart Keyless Entry System