CVE-2025-6029 - CVE House
Back to Database
Status published Critical CVE-2025-6029

KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack

Vulnerability Description

Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release.  CVE Record will be updated once this is clarified.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6029

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Danilo Erazo

Affected Vendor

Affected Software

Aftermarket Generic Smart Keyless Entry System
Vulnerable Versions:
KIA Ecuador Key Fobs version 2022/2023

Timeline

Official Publish: June 13th, 2025
Last Modified: June 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)