{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/bluetooth/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KARR BT","DR-100"],"_cs_severities":["high"],"_cs_tags":["ics","transportation-security","bluetooth","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Acrisure"],"content_html":"\u003cp\u003eAcrisure has identified a vulnerability in its KARR BT and DR-100 dealer-installed automotive anti-theft systems, affecting firmware versions released prior to July 20, 2026. The vulnerability, tracked as CVE-2026-18411, is rooted in the use of a hard-coded cryptographic key for Bluetooth authentication across all affected devices. This security flaw enables an attacker positioned within Bluetooth range of a targeted vehicle to bypass authentication mechanisms and issue unauthorized commands to the anti-theft controller. Potential impacts of successful exploitation include unauthorized unlocking of vehicle doors and the ability to immobilize the vehicle engine. Because this affects automotive security hardware deployed worldwide within the transportation sector, it poses a risk to vehicle integrity and owner safety. Users are strongly advised to apply the vendor-provided firmware update immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability affects Acrisure KARR BT and DR-100 systems deployed globally in the transportation systems sector. Exploitation requires no authentication and can be performed by an attacker in physical proximity to the vehicle via Bluetooth. If exploited, an attacker gains unauthorized control over critical vehicle functions, specifically door locks and engine immobilization, which could facilitate vehicle theft or disrupt vehicle operation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the firmware update released by Acrisure on July 20, 2026, to all affected KARR BT and DR-100 units following instructions at \u003ca href=\"https://www.karrsecurity.com/karr-security-firmware-update-instructions\"\u003ehttps://www.karrsecurity.com/karr-security-firmware-update-instructions\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eDisable Bluetooth connectivity on automotive aftermarket devices if not strictly required for daily operation until the firmware update is applied.\u003c/li\u003e\n\u003cli\u003eConduct a risk assessment for fleets or personal vehicles equipped with dealer-installed KARR security systems to identify vulnerable hardware versions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T16:38:30Z","date_published":"2026-08-04T16:38:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-acrisure-karr-bt-vulnerability/","summary":"A hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.","title":"Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100","url":"https://feed.craftedsignal.io/briefs/2026-08-acrisure-karr-bt-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Bluetooth","version":"https://jsonfeed.org/version/1.1"}