Junglewise Threat Intelligence

CVE-2025-6666: motogadget mo.lock Ignition Lock use of hard-coded cryptographic key in NFC Handler

CVE-2025-6666 · Severity: low · CVSS 2 · Published 2025-11-29

Executive brief

motogadget mo.lock is an ignition lock system that uses NFC (near-field communication) for authentication. A vulnerability allows an attacker with physical access to the device to manipulate the NFC Handler component using a hard-coded cryptographic key, potentially bypassing the ignition lock security mechanism. Exploitation is difficult and requires high technical complexity.

Technical details

The vulnerability exists in the NFC Handler component of motogadget mo.lock Ignition Lock, where a hard-coded cryptographic key is used for authentication or encryption operations. An attacker with physical proximity to the device can exploit this weakness through manipulation of NFC communication to bypass the lock mechanism. The attack vector is physical/adjacent-network, requiring close proximity to the device. Exploitation is complex and appears difficult to execute in practice. No patch information is currently available; the vendor was contacted early but did not respond.

Affected products

  • motogadget mo.lock Ignition Lock up to 20251125

Timeline

  • 2025-11-29: disclosed

References