PatchSiren cyber security CVE debrief
CVE-2025-70994 Yadea CVE debrief
CVE-2025-70994 covers a weak authentication issue in Yadea T5 Electric Bicycles. According to CISA, a local attacker who intercepts a legitimate key fob transmission may be able to forge signals and defeat the authentication mechanism. The advisory is framed as a physical-security risk with high integrity and availability impact, not as a remote software vulnerability.
- Vendor
- Yadea
- Product
- T5 Electric Bicycle
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-04-23
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-04-23
Who should care
Owners, operators, fleet managers, and service personnel responsible for Yadea T5 Electric Bicycles; also anyone securing parked units in public or semi-public locations.
Technical summary
The source advisory describes weak authentication in the Yadea T5 key-fob mechanism. The attack scenario requires local interception of a legitimate key fob transmission, followed by signal forgery to bypass authentication. The supplied CVSS v3.1 vector is AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H, indicating adjacent access, low complexity, no privileges, user interaction, and high integrity/availability impact.
Defensive priority
High
Recommended defensive actions
- Follow the CISA advisory for CVE-2025-70994 and monitor the official CVE/CISA references for updates.
- Keep affected systems up to date using vendor guidance where available.
- Use strong external physical locks and layered property security for parked bicycles.
- Reduce opportunities for local interception of key fob transmissions by limiting exposure in public areas.
- Contact Yadea through the vendor contact page for current support or remediation guidance.
Evidence notes
Primary evidence is CISA CSAF advisory ICSA-26-113-01, published 2026-04-23, which states: Yadea T5 Electric Bicycles have a weak authentication mechanism vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmissions. The same source notes that Yadea did not respond to CISA's coordination attempts and recommends keeping systems up to date and securing property with external mechanisms. The source corpus does not provide a KEV entry or ransomware-campaign association.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-70994 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-70994
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-70994 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-70994
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-113-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.