Government Advisory

Hard-Coded Encryption Key Flaw Found in Vehicle Alarm Systems

CISA · 4 Aug 2026
Key Takeaway If your business uses connected vehicles, fleet tracking, or IoT security devices, check with your vendor for firmware updates and avoid products known to use fixed, non-unique security keys.

CISA has issued an advisory about a security flaw affecting Acrisure's KARR BT and DR-100 vehicle security systems, widely used to protect cars from theft. The issue stems from the use of a hard-coded cryptographic key, meaning the same encryption key is embedded in every device rather than being unique to each unit.

This flaw, rated 8.1 out of 10 in severity, could allow an attacker to perform unauthorized vehicle control operations if exploited. The vulnerability affects firmware versions released before July 20, 2026, and impacts devices deployed worldwide within the transportation sector. Acrisure is headquartered in the United States.

While this advisory is targeted at vehicle security hardware rather than typical office IT, it's a useful reminder for any Australian small business that relies on connected devices, fleet vehicles, or IoT-enabled equipment: hard-coded credentials are a recurring and serious weakness across many industries, not just automotive.

IoT Security Vehicle Security CISA Advisory Hard-coded Credentials Fleet Security

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.