SB2026021824 - Multiple vulnerabilities in Micca Car Alarm System KE700



SB2026021824 - Multiple vulnerabilities in Micca Car Alarm System KE700

Published: February 18, 2026

Security Bulletin ID SB2026021824
Severity
Medium
Patch available
NO
Number of vulnerabilities 3
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2026-2540)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the authentication bypass using an alternate path or channel in the alarm system’s receiver. A remote attacker on the local network can capture and replay previously transmitted signals to clone the alarm key and gain access to the vehicle to unlock or lock the doors.


2) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-2539)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the affected system does not encrypt its data frames. A remote attacker on the local network can gain access to sensitive data.


3) Insufficient Entropy (CVE-ID: CVE-2026-2541)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient entropy issue. A remote attacker on the local network can guess the next valid rolling code and gain unauthorized access to the car.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.