PT-2025-25420 · Unknown · Kia-Branded Aftermarket Generic Smart Keyless Entry System
Danilo Erazo
·
Published
2025-06-13
·
Updated
2025-07-25
·
CVE-2025-6029
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N |
Name of the Vulnerable Software and Affected Versions
KIA-branded Aftermarket Generic Smart Keyless Entry System versions 2022 through 2025
Description
The issue is related to the use of fixed learning codes in the Key Fob Transmitter, which allows a replay attack. This affects KIA vehicles in Ecuador, primarily those using outdated key fobs with vulnerable chips. Attackers can exploit this to unlock vehicles remotely. The estimated number of affected devices is not specified.
Recommendations
For KIA-branded Aftermarket Generic Smart Keyless Entry System versions 2022 through 2025, consider disabling the keyless entry feature until a patch is available. Restrict access to the key fob transmitter to minimize the risk of exploitation. Avoid using the vulnerable chips HS2240 and EV1527 in the key fobs until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kia-Branded Aftermarket Generic Smart Keyless Entry System