CISA Warns of Critical Vulnerability in Acrisure Vehicle Security Systems
A hard-coded Bluetooth key in Acrisure KARR BT and DR-100 systems allows attackers to issue unauthorized commands, potentially controlling vehicle functions.

CISA has issued a critical advisory detailing a significant vulnerability affecting Acrisure KARR BT and DR-100 vehicle security systems. The flaw, identified as CVE-2026-18411, stems from the use of a shared, hard-coded Bluetooth authentication key across all affected devices. This weakness permits an attacker within Bluetooth range to issue unauthorized commands to the vehicle.
The potential impact of exploiting this vulnerability is severe. Attackers could gain control over critical vehicle functions, including unlocking doors, immobilizing the engine, and potentially other unauthorized operations. The CVSS score for this vulnerability is rated at 8.1 HIGH, underscoring the urgency for remediation.
The affected versions include Acrisure KARR BT firmware prior to July 20, 2026, and DR-100 firmware also prior to July 20, 2026. These systems are deployed worldwide within the Transportation Systems critical infrastructure sector, making the potential for widespread disruption considerable.
Acrisure Protection Group has responded by releasing a firmware update on July 20, 2026, to address the vulnerability. Users are advised to follow specific instructions provided by Acrisure to apply this update. The vulnerability is categorized under CWE-321, indicating a 'Use of Hard-coded Cryptographic Key'.
While CISA notes that no known public exploitation targeting this specific vulnerability has been reported at this time, the nature of the flaw presents a clear and present danger. The advisory emphasizes recommended practices for securing Industrial Control Systems (ICS), including minimizing network exposure, isolating control system networks behind firewalls, and using secure remote access methods like VPNs.
This incident highlights a persistent challenge in securing automotive and transportation-related IoT devices, where embedded security features can sometimes contain fundamental weaknesses. The reliance on hard-coded credentials, even for Bluetooth authentication, creates an easily exploitable attack vector if not properly managed and updated.
CISA encourages organizations to implement defensive measures and perform thorough impact and risk assessments before deploying any security updates. The agency also provides extensive resources on its ICS webpage for improving cybersecurity and mitigating threats to control systems.