Executive brief
The remote keyless entry system used in certain vehicles, including the 2024 Suzuki Swift, is vulnerable to a signal replay attack. An attacker within radio range can record the signals from a legitimate key fob and later use them to unlock or lock the vehicle without the owner's permission. This flaw allows unauthorized physical access to the vehicle's interior and could lead to theft of property or the vehicle itself.
Technical details
The vulnerability is a rolling-code roll-back (CWE-294) in the authentication and resynchronization logic of the Alps Alpine RKES (FCC ID CWTR53R0). An attacker within RF range (433 MHz) can capture two consecutive valid transmissions from a legitimate key fob. By replaying the first captured transmission, the attacker forces the system into a specific state that accepts the second captured transmission as valid, even if it has been used before. This bypasses the rolling-code security mechanism intended to prevent replay attacks. The flaw was confirmed on a 2024 Suzuki Swift, but likely affects other vehicles using the same hardware component.
Affected products
- Alps Alpine Co., Ltd. Remote Keyless Entry System (RKES) R53R0 FCC ID CWTR53R0; tested on 2024 Suzuki Swift
Timeline
- 2026-06-25: advisory: CVE-2026-49319 published by NVD and ASRG