Authentication bypass using an alternate path or channel in Car Alarm System KE700 - CVE-2026-2540

 

Authentication bypass using an alternate path or channel in Car Alarm System KE700 - CVE-2026-2540

Published: February 18, 2026


Vulnerability identifier: #VU123007
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2540
CWE-ID: CWE-288
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the authentication bypass using an alternate path or channel in the alarm system’s receiver. A remote attacker on the local network can capture and replay previously transmitted signals to clone the alarm key and gain access to the vehicle to unlock or lock the doors.


Affected software

Car Alarm System KE700

How to mitigate CVE-2026-2540

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins