PatchSiren

BYD CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH BYD CVE published 2026-05-19

CVE-2025-61081

CVE-2025-61081 describes a brute-force authentication weakness in BYD Atto3. According to the source record, an attacker can obtain a permanently available authentication key and use it to flash Electronic Parking Brake (EPB) and Supplemental Restraint System (SRS) related ECUs. NVD assigns the issue CVSS 3.1 7.5 HIGH and maps it to CWE-307; the NVD record is marked Deferred, so defenders should treat thi [truncated]