VYPR
Medium severity4.6NVD Advisory· Published May 29, 2026· Updated May 29, 2026

CVE-2026-49325

CVE-2026-49325

Description

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Physical attackers can bypass the anti-theft shutdown of the Indian Motorcycle Scout Bobber + Tech 2025 by interrupting the WCM wiring harness, leaving the motorcycle operable without PIN validation.

Vulnerability

The vulnerability resides in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year. The Wireless Control Module (WCM) signals a shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit or disconnected condition. This improper handling of physical conditions allows an attacker to bypass the anti-theft shutdown mechanism [1]. The affected model is specifically the 2025 model year.

Exploitation

A physical attacker with access to the WCM wiring harness can exploit this vulnerability. By interrupting the relevant wires (e.g., cutting or disconnecting them), the attacker can prevent the shutdown signal from being transmitted. Since the receiving ECU cannot differentiate between a valid shutdown pulse and an open circuit, the motorcycle remains fully operable even though the WCM never validated the rider's PIN. No authentication or special tools are required beyond physical access to the harness.

Impact

Successful exploitation allows an attacker to operate the motorcycle without authorization, effectively bypassing the PIN-based anti-theft system. The attacker gains the ability to start and ride the vehicle, leading to a complete loss of vehicle access control. The compromise affects the confidentiality (no theft protection) and integrity (operational status) of the system.

Mitigation

As of the publication date (2026-05-29), the vendor has not released a fix. Specific connector details have been withheld pending vendor remediation. Owners should be aware of the vulnerability and consider physical security measures to limit access to the WCM wiring harness until an official update is provided.

AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.