CVE-2026-1354
Last modified
CVE-2026-1354 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air firmware updating functionality to potentially upload malicious firmware to the motorcycle. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air firmware updating functionality to potentially upload malicious firmware to the motorcycle. The motorcycle must first be in Bluetooth pairing mode, and the attacker must be in proximity of the vehicle and understand the full pairing process, to be able to pair their device with the vehicle. The attacker's device must remain paired with and in proximity of the motorcycle for the entire duration of the firmware update.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Zero Motorcycles | Zero Motorcycles firmware | <= 44 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-1354?
How severe is CVE-2026-1354?
How do I fix CVE-2026-1354?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13534A vulnerability was detected in CherryHQ cherry-studio up to…5
- CVE-2026-13535A flaw has been found in CodeAstro Human Resource Management…6.3
- CVE-2026-13536A vulnerability has been found in GotoHTTP up to 10.2. This …4.3
- CVE-2026-13537A vulnerability was found in CodeAstro Human Resource Manage…4.3
- CVE-2026-13538A vulnerability was determined in Wavlink WL-NU516U1-A M16U1…6.3
- CVE-2026-13539A vulnerability was identified in Wavlink WL-NU516U1-A M16U1…8.8
- CVE-2026-13540A security flaw has been discovered in GitBucket up to 4.46.…6.3
- CVE-2026-13541A weakness has been identified in itsourcecode Hospital Mana…6.3
- CVE-2026-13542A security vulnerability has been detected in itsourcecode H…6.3
- CVE-2026-13543A vulnerability was detected in Documenso up to 2.11.0. Affe…5.6
- CVE-2026-13544A flaw has been found in Feehi CMS up to 2.1.1. Affected by …6.3
- CVE-2026-13545A vulnerability has been found in D-Link DCS-935L 1.10.01. T…8.8
Are you affected by CVE-2026-1354?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
