PT-2026-41983 · Byd · Atto 3

Published

2026-05-19

·

Updated

2026-05-20

·

CVE-2025-61081

CVSS v3.1

7.5

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions BYD Atto3 (affected versions not specified)
Description An attacker can obtain a permanently available authentication key through a Brute Force attack. This key allows unauthorized flashing of the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related Electronic Control Units (ECUs), which are embedded systems that control specific vehicle functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2025-61081

Affected Products

Atto 3