CVE-2025-70994
7.3Yadea · T5 Electric Bicycles
Yadea T5 Electric Bicycles manufactured in or after 2024 use an insecure fixed-code RF protocol for keyless entry, permitting unauthorized vehicle operation via signal replay attacks.
Executive summary
Yadea T5 Electric Bicycles possess a critical authentication flaw in their keyless entry system that allows an attacker to intercept signals and bypass security to operate the vehicle.
Vulnerability
The keyless entry system implements the EV1527 fixed-code RF protocol without rolling codes or cryptographic challenge-response mechanisms, which enables an unauthenticated attacker to perform signal forgery and replay attacks.
Business impact
The successful exploitation of this vulnerability grants an attacker full control to operate the affected electric bicycles, resulting in potential theft or unauthorized usage. Given the CVSS score of 7.3, this represents a significant physical security risk that necessitates prompt attention to mitigate unauthorized access and potential liability.
Remediation
Immediate Action: Contact Yadea support or authorized dealers to determine if a firmware update or hardware modification is available to address the lack of rolling codes.
Proactive Monitoring: Monitor the immediate physical vicinity of the vehicle for suspicious activity involving RF signal capture devices, particularly in public or high-traffic areas.
Compensating Controls: Since this is a physical security flaw, consider using secondary mechanical locks, such as heavy-duty chains or disc locks, to prevent vehicle operation in the event of an electronic bypass.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub repository referenced in the CVE record.
Analyst recommendation
The reliance on a static, insecure RF protocol for access control creates an elevated risk of vehicle theft. Owners and fleet operators should prioritize the implementation of physical security measures while awaiting guidance from the manufacturer regarding permanent remediation, as the current electronic system provides insufficient protection against determined attackers.