Executive brief
A security flaw in the 2025 Indian Motorcycle Scout Bobber + Tech model allows an attacker with physical or local network access to bypass the vehicle's anti-theft system. By disrupting the motorcycle's internal communication network, an attacker can prevent the security module from sending a shutdown command, allowing the bike to be started and ridden without a valid key. This poses a significant risk of vehicle theft and unauthorized operation.
Technical details
The vulnerability stems from an expected behavior violation in the CAN bus implementation of the Wireless Control Module (WCM). An attacker can use a CAN error-frame injection technique to target periodic WCM transmissions, driving the transmit error counter (TEC) past the bus-off threshold (255). Once in the 'bus-off' state, the WCM ceases all transmissions, including the immobilizer's shutdown command. Because peer Electronic Control Units (ECUs) do not treat the absence of WCM messages as a security exception, they continue normal operation, effectively bypassing the anti-theft mechanism. This requires adjacent network access to the vehicle's CAN bus.
Affected products
- Indian Motorcycle Scout Bobber + Tech 2025
Timeline
- 2026-05-29: disclosed: Vulnerability published to NVD