Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100
A hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.
Acrisure has identified a vulnerability in its KARR BT and DR-100 dealer-installed automotive anti-theft systems, affecting firmware versions released prior to July 20, 2026. The vulnerability, tracked as CVE-2026-18411, is rooted in the use of a hard-coded cryptographic key for Bluetooth authentication across all affected devices. This security flaw enables an attacker positioned within Bluetooth range of a targeted vehicle to bypass authentication mechanisms and issue unauthorized commands to the anti-theft controller. Potential impacts of successful exploitation include unauthorized unlocking of vehicle doors and the ability to immobilize the vehicle engine. Because this affects automotive security hardware deployed worldwide within the transportation sector, it poses a risk to vehicle integrity and owner safety. Users are strongly advised to apply the vendor-provided firmware update immediately.
Impact
This vulnerability affects Acrisure KARR BT and DR-100 systems deployed globally in the transportation systems sector. Exploitation requires no authentication and can be performed by an attacker in physical proximity to the vehicle via Bluetooth. If exploited, an attacker gains unauthorized control over critical vehicle functions, specifically door locks and engine immobilization, which could facilitate vehicle theft or disrupt vehicle operation.
Recommendation
- Apply the firmware update released by Acrisure on July 20, 2026, to all affected KARR BT and DR-100 units following instructions at https://www.karrsecurity.com/karr-security-firmware-update-instructions.
- Disable Bluetooth connectivity on automotive aftermarket devices if not strictly required for daily operation until the firmware update is applied.
- Conduct a risk assessment for fleets or personal vehicles equipped with dealer-installed KARR security systems to identify vulnerable hardware versions.
Immediate actions
Patch all vulnerable KARR BT and DR-100 firmware