CVE-2026-2539 Details
Description
The RF communication protocol in the Micca KE700 car alarm system does not encrypt its data frames. An attacker with a radio interception tool (e.g., SDR) can capture the random number and counters transmitted in cleartext, which is sensitive information required for authentication.
A vulnerability exists in the Micca KE700 car alarm system due to the RF communication protocol's lack of encryption, leaving data frames exposed. This flaw allows an attacker with a radio interception tool to capture sensitive information, such as the Key Fob ID and rolling code counters, transmitted in cleartext. The KE700 version is affected, and the vulnerability arises from a fundamental design flaw in the system's rolling code implementation, which does not secure transmissions, enabling potential brute-force attacks.
It is recommended to implement encryption for the entire transmission frame using a standard symmetric algorithm, such as AES-128. Additionally, the encrypted payload should include a Message Authentication Code (MAC) to prevent tampering or spoofing.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 15, 2026CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://asrg.io/security-advisories/cve-2026-2539-micca-ke700-cleartext-transmission-of-key-fob-id/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Micca KE700 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 15, 2026 | New CVE Received | [email protected] |
Volerion