CVE-2025-6030

CRITICAL

Cyclone Matrix TRF Smart - Replay Attack

Title source: llm
STIX 2.1

Description

Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto.  Attack confirmed on other KIA Models in Ecuador.

Scores

CVSS v4 9.4
EPSS 0.0012
EPSS Percentile 31.1%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-294 CWE-307
Status published
Products (1)
Autoeastern/Cyclone Matrix TRF 2024 - 2025
Published Jun 13, 2025
Tracked Since Feb 18, 2026