top of page
perceptive_background_267k.jpg

Acrisure KARR BT and DR-100

Published:

4 augustus 2026 om 14:00:00

Alert date:

4 augustus 2026 om 19:02:18

Source:

cisa.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure

CISA published an ICS advisory for Acrisure KARR BT and DR-100 automotive anti-theft systems, disclosing a critical vulnerability (CVE-2026-18411) involving the use of a shared hard-coded Bluetooth authentication key across affected devices. An attacker within Bluetooth range can exploit this weakness to issue unauthorized commands to vehicles, enabling unauthorized door unlocking or engine immobilization. The vulnerability affects KARR BT and DR-100 firmware versions prior to July 20, 2026, and is classified as HIGH severity with a CVSS v3.1 score of 8.1. Acrisure Protection Group released a firmware patch on July 20, 2026, to remediate the issue. Affected systems fall under the Transportation Systems critical infrastructure sector and are deployed worldwide. The vulnerability was discovered and reported by a research team from UC San Diego. No known public exploitation has been reported at the time of publication. Users are advised to apply the firmware update and follow vendor instructions at karrsecurity.com.

Technical details

Mitigation steps:

Affected products:

Acrisure KARR BT
Acrisure DR-100

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page