


Perceptive Security
SOC/SIEM Consultancy

Acrisure KARR BT and DR-100
Published:
4 augustus 2026 om 12:00:00
Alert date:
4 augustus 2026 om 17:02:18
Source:
cisa.gov
Mobile & IoT, Critical Infrastructure
CISA published an ICS advisory for Acrisure KARR BT and DR-100 automotive anti-theft systems, disclosing a critical vulnerability (CVE-2026-18411) involving the use of a shared hard-coded Bluetooth authentication key across affected devices. An attacker within Bluetooth range can exploit this weakness to issue unauthorized commands to vehicles, enabling unauthorized door unlocking or engine immobilization. The vulnerability affects KARR BT and DR-100 firmware versions prior to July 20, 2026, and is classified as HIGH severity with a CVSS v3.1 score of 8.1. Acrisure Protection Group released a firmware patch on July 20, 2026, to remediate the issue. Affected systems fall under the Transportation Systems critical infrastructure sector and are deployed worldwide. The vulnerability was discovered and reported by a research team from UC San Diego. No known public exploitation has been reported at the time of publication. Users are advised to apply the firmware update and follow vendor instructions at karrsecurity.com.
Technical details
Mitigation steps:
Affected products:
Acrisure KARR BT
Acrisure DR-100
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-216-01.json
https://www.cve.org/CVERecord?id=CVE-2026-18411
https://www.karrsecurity.com/karr-security-firmware-update-instructions
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
https://cwe.mitre.org/data/definitions/321.html
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
