PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-70994 Yadea CVE debrief

CVE-2025-70994 covers a weak authentication issue in Yadea T5 Electric Bicycles. According to CISA, a local attacker who intercepts a legitimate key fob transmission may be able to forge signals and defeat the authentication mechanism. The advisory is framed as a physical-security risk with high integrity and availability impact, not as a remote software vulnerability.

Vendor
Yadea
Product
T5 Electric Bicycle
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-23
Original CVE updated
2026-04-23
Advisory published
2026-04-23
Advisory updated
2026-04-23

Who should care

Owners, operators, fleet managers, and service personnel responsible for Yadea T5 Electric Bicycles; also anyone securing parked units in public or semi-public locations.

Technical summary

The source advisory describes weak authentication in the Yadea T5 key-fob mechanism. The attack scenario requires local interception of a legitimate key fob transmission, followed by signal forgery to bypass authentication. The supplied CVSS v3.1 vector is AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H, indicating adjacent access, low complexity, no privileges, user interaction, and high integrity/availability impact.

Defensive priority

High

Recommended defensive actions

  • Follow the CISA advisory for CVE-2025-70994 and monitor the official CVE/CISA references for updates.
  • Keep affected systems up to date using vendor guidance where available.
  • Use strong external physical locks and layered property security for parked bicycles.
  • Reduce opportunities for local interception of key fob transmissions by limiting exposure in public areas.
  • Contact Yadea through the vendor contact page for current support or remediation guidance.

Evidence notes

Primary evidence is CISA CSAF advisory ICSA-26-113-01, published 2026-04-23, which states: Yadea T5 Electric Bicycles have a weak authentication mechanism vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmissions. The same source notes that Yadea did not respond to CISA's coordination attempts and recommends keeping systems up to date and securing property with external mechanisms. The source corpus does not provide a KEV entry or ransomware-campaign association.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-70994 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-70994

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-70994 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-70994

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-113-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.