CVE-2026-49325
Last modified
CVE-2026-49325 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-49325?
How severe is CVE-2026-49325?
How do I fix CVE-2026-49325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49318Incorrect behavior order in the Infotainment / Digital Round…2.4
- CVE-2026-49319Remote Keyless Entry System (RKES), using the 433 MHz key fo…6.9
- CVE-2026-4932IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW10…4.2
- CVE-2026-49322Weak authentication in the Wireless Control Module (WCM) of …4.3
- CVE-2026-49323Weak authentication between the Wireless Control Module (WCM…4.3
- CVE-2026-49324Uncontrolled resource consumption in the Wireless Control Mo…4.6
- CVE-2026-49326Missing Authorization vulnerability in Apache HBase thrift a…6.5
- CVE-2026-49328Server-Side Request Forgery (SSRF) in the UrlImageConverter …5.3
- CVE-2026-49329A flaw was found in openshift/oauth-server. The OAuth login …7.5
- CVE-2026-4933Incorrect Authorization vulnerability in Drupal Unpublished …7.5
- CVE-2026-49331A flaw was found in openshift/oauth-proxy. On paths configur…6.5
- CVE-2026-49332A flaw was found in openshift/oauth-proxy. The proxy sets au…8.5
Are you affected by CVE-2026-49325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
