CVE-2022-27254

MEDIUM

Honda Civic 2018 Firmware - Authentication Bypass via RF Signal Replay Attack

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-27254. PoCs published by nonamecoder.

AI-analyzed exploit summary This repository provides a detailed writeup and proof-of-concept videos for CVE-2022-27254, a vulnerability in Honda's Remote Keyless System that allows replay attacks due to unencrypted RF signals. It includes affected vehicle models, tools used, and mitigation strategies.

Description

The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626.

Exploits (1)

nomisec WRITEUP 464 stars
by nonamecoder · poc
https://github.com/nonamecoder/CVE-2022-27254

This repository provides a detailed writeup and proof-of-concept videos for CVE-2022-27254, a vulnerability in Honda's Remote Keyless System that allows replay attacks due to unencrypted RF signals. It includes affected vehicle models, tools used, and mitigation strategies.

Classification
Writeup 100%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Honda Remote Keyless System (2016-2020 Honda Civic models)
No auth needed
Prerequisites: HackRF One · Gqrx · GNURadio · Proximity to target vehicle
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/nonamecoder/CVE-2022-27254
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://news.ycombinator.com/item?id=30804702
Exploit, Third Party Advisory x_refsource_misc
https://www.theregister.com/2022/03/25/honda_civic_hack/

Scores

CVSS v3 5.3
EPSS 0.0108
EPSS Percentile 60.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-294
Status published
Products (1)
honda/civic_2018_firmware
Published Mar 23, 2022
Tracked Since Feb 18, 2026