Acrisure KARR BT and DR-100 Bluetooth Flaw Enables Unauthorized Vehicle Commands
On August 4, 2026, CISA published an advisory on CVE-2026-18411 , a vulnerability affecting Acrisure KARR BT and DR-100 products. The issue stems from the
Illustrative image generated with AI
High-Severity Vulnerability in Acrisure Systems
On August 4, 2026, CISA published an advisory on CVE-2026-18411, a vulnerability affecting Acrisure KARR BT and DR-100 products.
The issue stems from the use of a hard-coded, shared cryptographic key. An attacker within Bluetooth range of the device could exploit it to send unauthorized commands to vehicle systems.
Firmware versions released before July_20_2026 are affected. The products are deployed worldwide in the transportation systems sector.
Potential Impact on Vehicles
The flaw could compromise the integrity and availability of functions controlled by the devices. Potentially executable actions include unlocking vehicle doors and immobilizing the engine.
CISA assigns the vulnerability a CVSS 3.1 score of 8.1 and a CVSS 4.0 score of 7.2, both classified as high severity. The advisory does not indicate a direct impact on data confidentiality.
According to CISA, there is no evidence of publicly reported, targeted exploitation of the vulnerability.
Updates and Risk Mitigation
The primary mitigation is to update KARR BT and DR-100 to an unaffected firmware version. Organizations should also reduce device exposure and prevent unnecessary Bluetooth access.
To limit potential propagation to other systems, CISA recommends:
- separating control networks from corporate networks using firewalls and network segmentation;
- securing remote access and using up-to-date VPNs where necessary;
- assessing the potential impact and risks of the update in advance;
- monitoring for anomalous behavior;
- reporting incidents according to internal procedures and to CISA.
Sources
This article is an original reworking based on the sources below.




