CVE-2025-6029 describes a critical vulnerability in KIA-branded Aftermarket Generic Smart Keyless Entry Systems, primarily distributed in Ecuador, where fixed learning codes for locking and unlocking vehicles allow for replay attacks. This flaw, rated 9.4 CRITICAL, has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability, as an attacker can unlock and potentially steal the vehicle. While no active exploitation or public exploit code is currently reported, the vulnerability has a high FAUCET Risk Score of 85/100, indicating significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| KIA | Aftermarket Generic Smart Keyless Entry System | KIA Ecuador Key Fobs version 2022/2023CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.