highOther

Acrisure KARR BT and DR-100 Hard-coded Bluetooth Key Vulnerability

First seen Aug 5, 2026 · Updated Aug 5, 2026 · CVSS 8.1

ICSautomotive-securitybluetoothhard-coded-credentialsIoTCISA-advisory

Acrisure KARR BT and DR-100 anti-theft systems use a shared, hard-coded Bluetooth authentication key across all affected devices, allowing an attacker within Bluetooth range to send unauthorized commands to a vehicle. This could enable unauthorized door unlocking or engine immobilization. Acrisure has released a firmware update (July 20, 2026) to address the flaw, and no public exploitation has been reported.

Technical Analysis

CVE-2026-18411 (CWE-321: Use of Hard-coded Cryptographic Key) affects Acrisure KARR BT and DR-100 dealer-installed automotive anti-theft systems running firmware prior to July 20, 2026. Because the Bluetooth authentication key is shared/static across devices rather than uniquely provisioned, an attacker within Bluetooth radio range with no authentication or user interaction (AV:A/AC:L/PR:N/UI:N) can replay or derive the key to issue unauthorized commands affecting vehicle integrity and availability (CVSS 3.1: 8.1 High, CVSS 4.0: 7.2 High). This is a physical/proximity-based attack vector rather than a network-remote exploit, limiting mass exploitation but enabling targeted vehicle compromise, theft, or tampering. This is an ICS/embedded automotive vulnerability with no plausible direct impact on AI agent, LLM, or RAG software systems, as it pertains solely to Bluetooth-based vehicle anti-theft hardware.

Affected Systems

Acrisure KARR BT firmware versions prior to July 20, 2026; Acrisure DR-100 firmware versions prior to July 20, 2026; dealer-installed automotive anti-theft systems (KARR Security System and SWDS) using shared Bluetooth authentication keys

Indicators of Compromise

  • No specific IOCs published; vulnerability is a design flaw (hard-coded key) rather than an active malware/campaign artifact

Remediation Steps

  1. 1

    Apply vendor firmware update

    Update affected KARR BT and DR-100 devices to the firmware released by Acrisure Protection Group on July 20, 2026, following instructions at karrsecurity.com.

  2. 2

    Limit Bluetooth exposure

    Minimize the time and range in which vehicle Bluetooth anti-theft modules are discoverable/paired to reduce attacker proximity opportunities.

  3. 3

    Network and system isolation

    For related control system components, ensure devices are not exposed to broader networks and are isolated behind firewalls where applicable.

  4. 4

    Monitor for anomalies

    Report any suspected unauthorized vehicle access or anomalous behavior to CISA and follow internal incident response procedures.

CVE / Advisory IDs

CVE-2026-18411

Industries Most Exposed

Transportation SystemsAutomotive

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.