CVE-2026-49319 PUBLISHED

Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack

Assigner: ASRG
Reserved: 29.05.2026 Published: 25.06.2026 Updated: 25.06.2026

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication. 

An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
CVSS Score: 6.9

Product Status

Vendor Alps Electric Co., Ltd.
Product Remote Keyless Entry System (RKES) R53R0
Versions Default: unknown
  • Version R53R0 is affected

Credits

  • Danilo Erazo (Automotive Cybersecurity Researcher) finder

References

Problem Types

  • CWE-294 Authentication Bypass by Capture-replay CWE

Impacts

  • Reusing Session IDs (aka Session Replay)
  • Sniffing Network Traffic