In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related ECUs.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 19 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized ECU Flashing via Brute-Forced Authentication Key | |
| Weaknesses | CWE-307 CWE-522 |
Tue, 19 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and Supplemental Restoration System (SRS) related ECUs. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-19T18:13:43.105Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61081
No data.
Status : Received
Published: 2026-05-19T18:16:19.767
Modified: 2026-05-19T18:16:19.767
Link: CVE-2025-61081
No data.
OpenCVE Enrichment
Updated: 2026-05-19T18:30:11Z