Weak Authentication in Indian Motorcycle Scout Bobber + Tech 2025 Model
CVE-2026-49322

4.1MEDIUM

What is CVE-2026-49322?

The Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model features a weak authentication implementation that can be exploited by an adjacent-network attacker. This vulnerability allows unauthorized access to the user-set unlock PIN by passively observing a single authentication exchange. Instead of employing robust cryptographic methods, the infotainment system's response is generated through a non-cryptographic operation, making the PIN mathematically recoverable from just one captured exchange. This flaw jeopardizes the integrity of the motorcycle's user-authentication process.

Affected Version(s)

Scout Bobber + Tech OEM Motorcycle 2025

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scott Sheahan, Rustic Security LLC
.