CVE-2025-61081
7.5BYD · Atto3
An authentication key in the BYD Atto3 can be obtained via a brute-force attack, leading to potential unauthorized access.
Executive summary
A vulnerability in the BYD Atto3 allows attackers to compromise authentication security through brute-force attacks.
Vulnerability
This vulnerability involves a weakness in the authentication mechanism where an attacker can perform brute-force attempts to obtain a permanently available authentication key. The attack is unauthenticated as it targets the authentication process itself.
Business impact
Successful exploitation of this flaw could allow an attacker to bypass security controls and gain unauthorized access to vehicle systems. Given the CVSS score of 7.5, this represents a significant risk to system integrity and user privacy. Unauthorized access could lead to potential control or data compromise depending on the level of vehicle integration.
Remediation
Immediate Action: Contact the vehicle manufacturer or authorized service centers to inquire about available firmware updates or security patches for the Atto3.
Proactive Monitoring: Monitor for any unusual diagnostic alerts or unauthorized remote access attempts if the vehicle is connected to telematics services.
Compensating Controls: Ensure the vehicle is parked in secure locations and disable unnecessary remote connectivity features if the manufacturer provides such options until a patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates prompt attention from owners and fleet managers. Users should prioritize communication with the vendor to verify the availability of an official security update to resolve this authentication weakness.