


Perceptive Security
SOC/SIEM Consultancy

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV152…
Published:
22 april 2026 om 22:00:00
Alert date:
23 april 2026 om 19:01:54
Source:
nvd.nist.gov
Mobile & IoT
Yadea T5 Electric Bicycles manufactured in 2024 and later contain a critical authentication vulnerability in their keyless entry system. The vulnerability stems from the use of the EV1527 fixed-code RF protocol without proper security mechanisms like rolling codes or cryptographic challenge-response. Attackers can perform replay attacks by intercepting legitimate key fob transmissions, allowing complete unauthorized vehicle operation. This represents a significant security flaw affecting the physical security of electric bicycles through RF signal manipulation.
Technical details
Mitigation steps:
Affected products:
Yadea T5 Electric Bicycles
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-70994
https://github.com/ktauchathuranga/CVE-2025-70994
https://github.com/ktauchathuranga/ghost-keys
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
