PT-2025-25420 · Unknown · Kia-Branded Aftermarket Generic Smart Keyless Entry System

Danilo Erazo

·

Published

2025-06-13

·

Updated

2025-07-25

·

CVE-2025-6029

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N
Name of the Vulnerable Software and Affected Versions KIA-branded Aftermarket Generic Smart Keyless Entry System versions 2022 through 2025
Description The issue is related to the use of fixed learning codes in the Key Fob Transmitter, which allows a replay attack. This affects KIA vehicles in Ecuador, primarily those using outdated key fobs with vulnerable chips. Attackers can exploit this to unlock vehicles remotely. The estimated number of affected devices is not specified.
Recommendations For KIA-branded Aftermarket Generic Smart Keyless Entry System versions 2022 through 2025, consider disabling the keyless entry feature until a patch is available. Restrict access to the key fob transmitter to minimize the risk of exploitation. Avoid using the vulnerable chips HS2240 and EV1527 in the key fobs until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2025-6029

Affected Products

Kia-Branded Aftermarket Generic Smart Keyless Entry System