MEDIUM 6.5

CVE-2026-49319: ALPS ALPINE RKES 433 MHz Keyless Entry Replay Attack (2024 Suzuki Swift)

A 433 MHz remote keyless entry system (RKES) made by ALPS ALPINE CO., LTD. (FCC ID CWTR53R0) is vulnerable to replay attacks. An attacker within radio range can record two consecutive transmissions from a legitimate key fob, then replay that same pair repeatedly to unlock or lock a vehicle. Security researchers confirmed this vulnerability on a 2024 Suzuki Swift, demonstrating that the rolling-code authentication mechanism can be defeated through systematic replay of captured signals.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.5 MEDIUM · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses (CWE)
CWE-294
Affected products
0 configuration(s)
Published / Modified
2026-06-25 / 2026-06-26

NVD description (verbatim)

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication.  An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can later replay the same pair of transmissions repeatedly. During testing, replaying the first captured transmission caused the RKES to enter a state in which replaying the second captured transmission resulted in a successful lock or unlock operation of the vehicle. Tested and confirmed on a 2024 Suzuki Swift (SWIFT ISG GLS AC 1.2 5P 4x2 TM).

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

The vulnerability exploits a flaw in the rolling-code implementation of the ALPS ALPINE RKES. Rolling codes are designed to prevent simple replay attacks by changing the authentication value with each transmission. However, this implementation permits an attacker to capture a valid pair of consecutive transmissions and later replay them in sequence. The attack succeeds because the RKES enters a permissive state after receiving the first replayed transmission, allowing the second replayed transmission to authenticate successfully. This breaks the cryptographic guarantee that rolling codes are meant to provide. The vulnerability is classified as CWE-294 (Use of Insufficiently Random Values), indicating the underlying issue may relate to improper state management or predictability in the authentication sequence.

Business impact

Vehicle owners relying on this keyless entry system face increased risk of vehicle theft or unauthorized access. Attackers can unlock vehicles without possessing the legitimate key fob, enabling theft or intrusion. For automotive manufacturers and insurance carriers, this represents both a safety liability and a potential recall or remediation expense. Fleet operators and rental agencies may face elevated loss rates. The vulnerability affects a specific model year (2024 Suzuki Swift), but similar RKES implementations from the same supplier may carry comparable risk.

Affected systems

Confirmed affected: 2024 Suzuki Swift (model SWIFT ISG GLS AC 1.2 5P 4x2 TM) equipped with the ALPS ALPINE RKES bearing FCC ID CWTR53R0 operating on 433 MHz. Other vehicle models and year ranges may be affected if they use the same RKES module or similar implementations from ALPS ALPINE. The scope of affected vehicles is not yet fully enumerated in public disclosures; verification with the manufacturer is advised for fleet or ownership scenarios.

Exploitability

Exploitability is moderate to high in practical scenarios. An attacker must be within RF range (typically tens of meters for 433 MHz systems) to capture transmissions and perform the replay attack. No sophisticated equipment beyond a software-defined radio (SDR) or similar RF capture device is required. The attack does not require physical access to the vehicle during the exploit itself, only proximity during the initial signal capture phase. Once a pair of transmissions is recorded, replay can occur at any later time and location, making this a viable attack for opportunistic theft or coordinated vehicle targeting.

Remediation

Primary remediation requires a firmware or hardware update to the RKES module to strengthen rolling-code implementation and prevent replay-after-reset attacks. Vehicle owners should contact their dealer or manufacturer for guidance on availability and scheduling of remediation. Interim mitigations include parking in secure, monitored locations (garages, well-lit areas with surveillance) and monitoring vehicle status through connected car apps if available. Manufacturers should issue an advisory with patch timelines and may consider extended warranty coverage for affected vehicles pending updates.

Patch guidance

Vehicle owners should check with their Suzuki dealer for service bulletins or recall notices related to RKES firmware updates. Manufacturers typically roll out such patches through dealership service channels rather than over-the-air updates. If a recall or service campaign is issued, prioritize scheduling the update promptly. Verify with the dealer that the update addresses CVE-2026-49319 specifically. For fleet operators, coordinate with Suzuki's commercial support team for bulk scheduling and documentation of remediation across the fleet.

Detection guidance

Detection of exploitation is challenging because replay attacks leave no obvious trace in vehicle logs. Monitor for anomalies such as: unexpected lock/unlock events when the legitimate key fob is not in use, or repeated failed access attempts in close temporal proximity. Modern vehicles with connected services (SOS, telemetry) may log access events; review those logs for unauthorized transactions. At a network level, security teams cannot directly intercept 433 MHz transmissions without RF monitoring equipment, but dealers and manufacturers can implement RF signal forensics during service if theft is suspected. Consumer detection relies primarily on attentiveness to vehicle status and use of secondary security features (steering wheel locks, GPS trackers).

Why prioritize this

This vulnerability should be prioritized based on impact and scope. Although the CVSS score is 6.5 (MEDIUM), the real-world risk is substantial because: (1) vehicle theft is a high-value crime; (2) the attack requires no sophisticated tools or insider knowledge; (3) exploitation directly leads to unauthorized vehicle access; (4) the vulnerability affects mass-market vehicles in active use; (5) remediation is still pending and not yet publicly rolled out. Organizations managing fleets of 2024 Suzuki Swifts should treat this as HIGH priority for remediation planning. Individual owners should increase monitoring and preventive measures immediately.

Risk score, explained

The CVSS 3.1 score of 6.5 reflects a Medium severity rating: Attack Vector (Adjacent) indicates the attacker must be within RF range; Attack Complexity is Low (no special conditions needed); Privilege or User Interaction is not required; the scope is Unchanged (impact limited to the vehicle itself); Confidentiality impact is None (data is not exposed); Integrity impact is High (vehicle control is compromised); Availability is None (vehicle is not disabled, but can be stolen). The score appropriately captures that exploitation is feasible and leads to significant loss of vehicle control, but does not involve data exfiltration or system-wide compromise. However, from a business perspective, the financial and safety implications elevate practical risk beyond the numerical score.

Frequently asked questions

Can a thief use this attack without my key fob present?

Yes. An attacker must record two consecutive transmissions while your legitimate key fob is in use (or in range), but once those transmissions are captured and stored, they can replay them to unlock your vehicle at any later time, from any location within RF range of the vehicle, without needing the original key fob.

Does this affect only 2024 Suzuki Swifts, or other vehicles too?

The vulnerability has been confirmed on the 2024 Suzuki Swift with the specific ALPS ALPINE RKES module (FCC ID CWTR53R0). Other Suzuki models or other manufacturers' vehicles may be affected if they use the same or similar RKES implementations. Check with your vehicle manufacturer or dealer for advisory status.

Is there a patch or firmware update available now?

As of the vulnerability publication date (June 2026), no public patch information is confirmed. Vehicle owners should contact their Suzuki dealer for the latest service bulletins and recall status. Remediation is likely to occur through dealership service or manufacturer software updates over the coming weeks.

What immediate steps should I take to protect my vehicle?

Park in secure, well-lit, and monitored locations when possible; consider additional physical security measures such as steering wheel locks or GPS trackers; review your vehicle's access logs if it has connected services (mobile app or SOS); monitor your insurance and consider filing a claim if unauthorized access occurs; and stay informed about recall announcements from Suzuki.

This analysis is provided for informational and educational purposes. SEC.co makes no warranty regarding the completeness or accuracy of this vulnerability intelligence. Organizations should verify all information against official vendor advisories and conduct independent risk assessments for their specific environments. No exploit code or weaponization guidance is provided herein. Vehicle owners should consult official Suzuki dealer advisories and manufacturer recommendations for remediation. This intelligence does not constitute legal advice, insurance guidance, or criminal investigation support. Source: NVD (public-domain), retrieved 2026-08-03. Analysis generated by SEC.co (claude-haiku-4-5).