Honda's vulnerability footprint is concentrated in vehicle systems and firmware, particularly across Civic model generations, with recurring exposure in authentication and certificate-validation mechanisms that are critical to vehicle-network security. This narrow, vehicle-focused profile reflects the embedded nature of automotive firmware and the authentication demands of modern connected-vehicle architectures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Honda over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20626MEDIUM The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack. | Mar 23, 2020 | 6.5 | 24 | NO | NO |
CVE-2022-27254MEDIUM The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows for a replay attack, a related issue to CVE-2019-20626. | Mar 23, 2022 | 5.3 | 23 | NO | NO |
CVE-2022-37305MEDIUM The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations and force a resynchronization after captur | Aug 24, 2022 | 6.4 | 22 | NO | NO |
CVE-2021-46145MEDIUM The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expiring rolling code and counter resynchronization. | Jan 6, 2022 | 5.3 | 21 | NO | NO |
CVE-2015-2943MEDIUM Honda Moto LINC 1.6.1 does not verify SSL certificates. | Sep 6, 2017 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Honda.
Media articles that mention a CVE ID that affects a product developed by Honda — matched by CVE ID, not by vendor name.