Executive brief
A vulnerability in the Parani M10 motorcycle intercom allows an unauthorized person within Bluetooth range to crash the device or disrupt its operation. By sending specially crafted signals, an attacker can force the headset to reboot or disconnect from the rider's phone, potentially causing a loss of communication or navigation audio during use. This issue requires no user interaction and can be triggered as long as the attacker is in physical proximity to the device.
Technical details
The Parani M10 intercom firmware (v2.1.3) exposes an unauthenticated Bluetooth Classic RFCOMM service on channels 10 and 12. The vulnerability stems from improper input validation (CWE-120) within the command-processing mechanism. An attacker within Bluetooth range can establish a direct RFCOMM connection without pairing or user consent and transmit oversized frames to trigger a buffer overflow. This results in a device crash or reboot, requiring manual intervention to restore service. Additionally, the lack of authentication allows for Man-in-the-Middle (MITM) scenarios where an attacker can inject arbitrary audio or forcibly disconnect authorized mobile devices.
Affected products
- Parani M10 Motorcycle Intercom 2.1.3
Timeline
- 2026-04-13: advisory: Initial CVE publication
- 2026-05-10: other: CISA-ADP enrichment added CVSS and CWE details