No advisories yet.
Solution
Use a positive-validation heartbeat: the receiving ECU should require a periodic rising-edge or signed message from the WCM and treat its absence as the shutdown command (fail-secure). Combine with CAN-A liveness validation. Add tamper-evident sealing on the WCM connector.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://cwe.mitre.org/data/definitions/1384.html |
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Indian Motorcycle
Indian Motorcycle scout Bobber + Tech |
|
| Vendors & Products |
Indian Motorcycle
Indian Motorcycle scout Bobber + Tech |
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation. | |
| Title | Indian Scout Bobber 2025 WCM voltage-based shutdown | |
| Weaknesses | CWE-1384 CWE-693 CWE-754 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ASRG
Published:
Updated: 2026-05-29T15:27:16.405Z
Reserved: 2026-05-29T07:26:43.199Z
Link: CVE-2026-49325
Updated: 2026-05-29T15:27:13.644Z
Status : Deferred
Published: 2026-05-29T14:16:33.067
Modified: 2026-05-29T15:11:03.853
Link: CVE-2026-49325
No data.
OpenCVE Enrichment
Updated: 2026-05-29T16:00:15Z