CVE-2025-70994

high

Description

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmission, allowing for complete unauthorized vehicle operation via a replay attack.

References

https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-01

https://github.com/ktauchathuranga/ghost-keys

https://github.com/ktauchathuranga/CVE-2025-70994

Details

Source: Mitre, NVD

Published: 2026-04-23

Updated: 2026-04-24

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.00031