Junglewise Threat Intelligence

CVE-2025-70994: Yadea T5 Electric Bicycle

CVE-2025-70994 · Severity: high · CVSS 7.3 · Published 2026-04-23

Executive brief

Yadea T5 Electric Bicycles utilize a weak authentication mechanism vulnerable to signal forgery. A local attacker can intercept legitimate key fob transmissions to unlock and start the vehicle, potentially leading to theft.

Affected products

  • Yadea T5 Electric Bicycle all versions

Timeline

  • 2026-04-23: disclosed
  • 2026-04-23: advisory: Initial publication of ICSA-26-113-01

References