← All guides
Guide

Hard-Coded Crypto Keys in Automotive Anti-Theft Systems Expose Vehicles to Remote Unlock

CISA warns that Acrisure's KARR anti-theft systems share a single Bluetooth key across all devices—attackers in range can unlock doors or disable engines. A stark reminder that vendor security matters.

Shared Keys, Shared Risk

CISA issued an advisory for a critical vulnerability (CVE-2026-18411, CVSS 8.1) in Acrisure's KARR BT and DR-100 automotive anti-theft systems. The flaw stems from a hard-coded Bluetooth authentication key shared across all affected devices worldwide. An attacker within Bluetooth range can exploit this weakness to send unauthorized commands—unlocking doors, immobilizing engines, or accessing other vehicle functions. Acrisure released a firmware update on July 20, 2026, but deployed systems require manual patching.

Why SMBs Should Care

This incident underscores a broader lesson for IT leaders: vendor security practices directly impact your risk posture, even in seemingly niche products. Hard-coded credentials—whether in IoT devices, network appliances, or third-party software—create systemic vulnerabilities that can't be mitigated through perimeter defenses alone. For SMBs managing fleets, connected devices, or supply chain partners, this is a reminder to audit vendor security practices, enforce firmware update policies, and maintain an inventory of all connected systems. If a car alarm can ship with a universal key, what about your building access controllers, IP cameras, or industrial sensors?

Read the full CISA advisory

Need help assessing vendor risk or securing your connected infrastructure? O-Cyrus helps SMBs identify hidden vulnerabilities in third-party systems and build practical security programs that scale. Contact our team or explore our security services.

Related services

Need a hand with this?

O-Cyrus helps small businesses with websites, DNS, custom apps, and the everyday tech that keeps things running.

Talk to us →