Weak Authentication in Indian Motorcycle Scout Bobber + Tech 2025 Model
CVE-2026-49322
4.1MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 29 May 2026
What is CVE-2026-49322?
The Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model features a weak authentication implementation that can be exploited by an adjacent-network attacker. This vulnerability allows unauthorized access to the user-set unlock PIN by passively observing a single authentication exchange. Instead of employing robust cryptographic methods, the infotainment system's response is generated through a non-cryptographic operation, making the PIN mathematically recoverable from just one captured exchange. This flaw jeopardizes the integrity of the motorcycle's user-authentication process.
Affected Version(s)
Scout Bobber + Tech OEM Motorcycle 2025
References
CVSS V4
Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Scott Sheahan, Rustic Security LLC
