CISA flags a shared Bluetooth key in dealer-fitted car alarms that can immobilize engines
An advisory published August 4 said KARR anti-theft systems used one Bluetooth authentication key across devices, letting anyone within radio range open the doors and stop the engine.
The US Cybersecurity and Infrastructure Security Agency published an advisory on August 4 covering the KARR Security System and SWDS anti-theft systems, aftermarket equipment installed by dealers rather than fitted by the manufacturer. The agency said the devices used a Bluetooth authentication key shared across units, allowing an attacker within Bluetooth range to issue unauthorized commands to a vehicle, including releasing the door locks and immobilizing the engine.
The flaw is tracked as CVE-2026-18411 and classified under CWE-321, use of a hard-coded cryptographic key. CISA scored it 8.1 on version 3.1 of the common vulnerability scoring system and 7.2 on version 4.0, both in the high band. The affected products are Acrisure KARR BT firmware and Acrisure DR-100 firmware in versions earlier than a July 20, 2026 release. The advisory listed the vendor as based in the United States, deployment as worldwide, and the sector as transportation systems.
Acrisure Protection Group released firmware addressing the vulnerability on July 20, fifteen days before the advisory appeared, and CISA pointed owners to the KARR product site for instructions. The vulnerability was reported to the agency by eight researchers at the University of California, San Diego.
The advisory gave no figure for how many vehicles carry an affected module, and described no mechanism by which an owner would learn that a dealer-installed accessory needed reflashing.
Source: CISA, August 4, 2026.
Source: CISA ICS advisory ICSA-26-216-01