CVE-2025-56448

The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:positron:px360bt_firmware:rev8:*:*:*:*:*:*:*
cpe:2.3:h:positron:px360bt:8200101542:*:*:*:*:*:*:*

History

14 Oct 2025, 19:33

Type Values Removed Values Added
CPE cpe:2.3:o:positron:px360bt_firmware:rev8:*:*:*:*:*:*:*
cpe:2.3:h:positron:px360bt:8200101542:*:*:*:*:*:*:*
First Time Positron
Positron px360bt Firmware
Positron px360bt
References () https://medium.com/@wagneralves_87750/cve-2025-56448-replay-attack-vulnerability-in-positron-px360bt-car-alarm-system-c9f1ccea6ebe - () https://medium.com/@wagneralves_87750/cve-2025-56448-replay-attack-vulnerability-in-positron-px360bt-car-alarm-system-c9f1ccea6ebe - Exploit, Third Party Advisory
References () https://positron.com.br/blog/positron-lanca-alarme-px360bt-starter/ - () https://positron.com.br/blog/positron-lanca-alarme-px360bt-starter/ - Product

15 Sep 2025, 21:15

Type Values Removed Values Added
CWE CWE-294
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

15 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 20:15

Updated : 2025-10-14 19:33


NVD link : CVE-2025-56448

Mitre link : CVE-2025-56448

CVE.ORG link : CVE-2025-56448


JSON object : View

Products Affected

positron

  • px360bt
  • px360bt_firmware
CWE
CWE-294

Authentication Bypass by Capture-replay