Bluetooth Exploit in Zero Motorcycles Firmware by Zero Motorcycles
CVE-2026-1354

5.9MEDIUM

Key Information:

Vendor
CVE Published:
21 April 2026

What is CVE-2026-1354?

Zero Motorcycles firmware versions 44 and earlier contain a vulnerability that allows a nearby attacker to forcibly pair their device via Bluetooth with the motorcycle. Once a successful pairing occurs, the attacker can leverage the motorcycle's over-the-air firmware update capability, potentially uploading harmful firmware to the vehicle. The attack requires the motorcycle to be in Bluetooth pairing mode, and the attacker must maintain proximity to the vehicle for the duration of the firmware upload.

Affected Version(s)

Zero Motorcycles firmware 0 <= 44

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Persephone Karnstein of Bureau Veritas Cybersecurity North America reported this vulnerability to CISA.
.