All Security Advisories
CVE-2026-49319Jun 25, 2026

Suzuki Swift (2024): rolling-code keyless entry defeated by RollBack-style replay, enabling unauthorized lock/unlock

Description

The Remote Keyless Entry System (RKES) of the Suzuki Swift (2024 model year) is vulnerable to a RollBack-style capture-replay attack against its rolling-code scheme. An attacker within radio range who passively captures a short sequence of the legitimate key fob's transmissions can later replay them to force the receiver to resynchronize and then accept a previously valid code, allowing the vehicle doors to be unlocked (and locked) without the owner's key fob. Because the captured transmissions remain usable after the fact, the rolling-code anti-replay protection — the RKES's primary defense — is defeated.

Impact is limited to unauthorized actuation of the door lock/unlock function and the resulting access to the vehicle interior. The weakness does not by itself defeat the engine immobilizer or allow the vehicle to be driven away.

Specific signal-capture and replay procedures, captured signal data, radio parameters, and the proof-of-concept have been withheld to avoid enabling reproduction while the issue is unremediated.

Recommended remediation:

Replace counter-based rolling codes with fresh-challenge cryptographic authentication (for example a bidirectional challenge-response keyed from a per-vehicle secret held in a secure element), reject stale or rolled-back counter values, and constrain resynchronization so that previously transmitted codes can never be re-accepted. Distance-bounding (e.g., UWB) further mitigates replay and relay against keyless entry.

References

Reporter: Danilo Erazo (independent automotive cybersecurity researcher)
Attack-class background: RollBack — a time-agnostic replay attack against automotive RKES (USENIX Security 2022)

Credits

Danilo Erazo (independent automotive cybersecurity researcher) (finder)

Timeline

Reported to ASRG by the finder under coordinated disclosure.

2026-06-25: Advisory published by ASRG. Vendor remediation pending.

Advisory Details

Affected Products
Suzuki Motor Corporation — Suzuki Swift, 2024 model year (observed on the SWIFT ISG GLS trim); Remote Keyless Entry System (RKES) rolling-code key fob, FCC ID CWTR53R0.
Problem Type
CWE-294 Authentication Bypass by Capture-replay
CAPEC ID
CAPEC-60 Reusing Session IDs (aka Session Replay)
CVSS 3.1
5.4
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N
CVSS 4.0
5.3
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Published
Jun 25, 2026
View on NVD