Junglewise Threat Intelligence

CVE-2025-61081: BYD Atto 3 authentication bypass via brute force in EPB and SRS ECUs

CVE-2025-61081 · Severity: info · Published 2026-05-19

Executive brief

A security flaw in the BYD Atto 3 electric vehicle allows an attacker to guess a permanent authentication key through a brute-force attack. This key provides unauthorized access to critical vehicle systems, including the Electronic Parking Brake and the Supplemental Restraint System (airbags). If exploited, an attacker could potentially interfere with the vehicle's safety functions, posing a significant risk to passenger safety and vehicle operation.

Technical details

The BYD Atto 3 is vulnerable to a brute-force attack against its authentication mechanism, which protects access to internal Electronic Control Units (ECUs). The vulnerability stems from the use of a static or predictable authentication key that, once discovered, remains permanently valid. An attacker with local or physical access to the vehicle's diagnostic interface can exploit this to gain 'flash' privileges. This allows for the modification of firmware on safety-critical components, specifically the Electronic Parking Brake (EPB) and the Supplemental Restraint System (SRS/Airbags). No patch information was provided in the initial advisory.

Affected products

  • BYD Atto 3

Timeline

  • 2026-05-19: disclosed: Initial NVD publication date

References