The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.
References
Link | Resource |
---|---|
https://medium.com/@wagneralves_87750/cve-2025-56448-replay-attack-vulnerability-in-positron-px360bt-car-alarm-system-c9f1ccea6ebe | Exploit Third Party Advisory |
https://positron.com.br/blog/positron-lanca-alarme-px360bt-starter/ | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
14 Oct 2025, 19:33
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:positron:px360bt_firmware:rev8:*:*:*:*:*:*:* cpe:2.3:h:positron:px360bt:8200101542:*:*:*:*:*:*:* |
|
First Time |
Positron
Positron px360bt Firmware Positron px360bt |
|
References | () https://medium.com/@wagneralves_87750/cve-2025-56448-replay-attack-vulnerability-in-positron-px360bt-car-alarm-system-c9f1ccea6ebe - Exploit, Third Party Advisory | |
References | () https://positron.com.br/blog/positron-lanca-alarme-px360bt-starter/ - Product |
15 Sep 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-294 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
15 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 20:15
Updated : 2025-10-14 19:33
NVD link : CVE-2025-56448
Mitre link : CVE-2025-56448
CVE.ORG link : CVE-2025-56448
JSON object : View
Products Affected
positron
- px360bt
- px360bt_firmware
CWE
CWE-294
Authentication Bypass by Capture-replay