CVE-2025-56448
Last modified
CVE-2025-56448 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Positron | Px360bt Firmware | rev8 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-56448?
How severe is CVE-2025-56448?
How do I fix CVE-2025-56448?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-56431Directory Traversal vulnerability in Fearless Geek Media Fea…7.5
- CVE-2025-56432A cross-site scripting (XSS) vulnerability exists in Nagios …6.1
- CVE-2025-56435SQL Injection vulnerability in FoxCMS v1.2.6 and before allo…5.3
- CVE-2025-56438An issue in the firmware update mechanism of Nous W3 Smart W…6.8
- CVE-2025-5644A vulnerability, which was classified as problematic, has be…2.5
- CVE-2025-56447TM2 Monitoring v3.04 contains an authentication bypass and p…9.8
- CVE-2025-56449A security vulnerability was identified in Obsidian Schedule…8.2
- CVE-2025-5645A vulnerability, which was classified as problematic, was fo…2.5
- CVE-2025-56450Log2Space Subscriber Management Software 1.1 is vulnerable t…6.5
- CVE-2025-56451Cross site scripting vulnerability in seeyon Zhiyuan A8+ Col…6.1
- CVE-2025-5646A vulnerability has been found in Radare2 5.9.9 and classifi…2.5
- CVE-2025-56463Mercusys MW305R 3.30 and below is has a Transport Layer Secu…6.8
Are you affected by CVE-2025-56448?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
