Hard‑coded Bluetooth Key (CVE‑2026‑18411) Enables Unauthorized Vehicle Control in Acrisure KARR BT & DR‑100
What It Is – A hard‑coded cryptographic key is shared across Acrisure KARR BT and DR‑100 anti‑theft devices. An attacker within Bluetooth range can use the key to send forged commands, unlocking doors or immobilizing the engine.
Exploitability – The vulnerability is publicly disclosed (CVE‑2026‑18411) with a CVSS v3 score of 8.1 (High). No public exploit code is known, but the attack requires only proximity and the known key, making exploitation feasible for a motivated adversary.
Affected Products – Acrisure KARR BT firmware < July 20 2026 and Acrisure DR‑100 firmware < July 20 2026 (both classified as “known_affected”).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls – Hard‑coded keys violate logical‑access and authentication requirements (CC6.1, CC6.2). Demonstrating proper key‑management is essential evidence for auditors.
- Continuous Monitoring – Tracking firmware versions and patch status provides real‑time proof that the organization maintains a defensible security posture.
- Enterprise Procurement – Buyers in transportation and logistics now demand verifiable SOC 2 controls around IoT/vehicle‑telematics; a lapse can block contracts.
Recommended Actions
- Deploy Acrisure’s July 20 2026 firmware update to all KARR BT and DR‑100 units immediately.
- Inventory every deployed device, record firmware levels, and map them to the SOC 2 Access‑Control policy.
- Implement automated version‑checking (e.g., a CMDB integration) to generate audit‑ready evidence of ongoing compliance.
- Review and tighten Bluetooth authentication procedures, ensuring no hard‑coded secrets remain in future releases.
Source: CISA Advisory – ICSA‑26‑216‑01