CVE-2026-2541

MEDIUM

Micca KE700 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing only 64 possible combinations. This low entropy allows an attacker to perform a brute-force attack against one component of the rolling code. Successful exploitation simplify an attacker to predict the next valid rolling code, granting unauthorized access to the vehicle.

Scores

CVSS v4 6.4
EPSS 0.0003
EPSS Percentile 10.3%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:H/V:D/RE:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-331
Status published
Products (2)
Micca Auto Electronics Co., Ltd./Car Alarm System KE700 KE700
Micca Auto Electronics Co., Ltd./Car Alarm System KE700 KE700+
Published Feb 15, 2026
Tracked Since Feb 18, 2026