Executive brief
motogadget mo.lock is an ignition lock system that uses NFC (near-field communication) for authentication. A vulnerability allows an attacker with physical access to the device to manipulate the NFC Handler component using a hard-coded cryptographic key, potentially bypassing the ignition lock security mechanism. Exploitation is difficult and requires high technical complexity.
Technical details
The vulnerability exists in the NFC Handler component of motogadget mo.lock Ignition Lock, where a hard-coded cryptographic key is used for authentication or encryption operations. An attacker with physical proximity to the device can exploit this weakness through manipulation of NFC communication to bypass the lock mechanism. The attack vector is physical/adjacent-network, requiring close proximity to the device. Exploitation is complex and appears difficult to execute in practice. No patch information is currently available; the vendor was contacted early but did not respond.
Affected products
- motogadget mo.lock Ignition Lock up to 20251125
Timeline
- 2025-11-29: disclosed