VYPR

KE700

by Micca

CVEs (2)

  • CVE-2026-2541MedFeb 15, 2026
    risk 0.42cvss epss 0.00

    The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing only 64 possible combinations. This low entropy allows an attacker to perform a brute-force attack against one component of the rolling code. Successful exploitation simplify an attacker to predict the next valid rolling code, granting unauthorized access to the vehicle.

  • CVE-2026-2539MedFeb 15, 2026
    risk 0.37cvss epss 0.00

    The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g., SDR) can capture the random number and counters transmitted in cleartext, which is sensitive information required for authentication.