Junglewise Threat Intelligence

CVE-2026-49317: Indian Motorcycle Scout Bobber Infotainment PIN bypass

CVE-2026-49317 · Severity: low · CVSS 2.4 · Published 2026-05-29

Technologies: Indian Motorcycle Scout Bobber + Tech 2025. Vendors: Indian Motorcycle.

Executive brief

A security flaw in the infotainment system of the 2025 Indian Motorcycle Scout Bobber + Tech allows an unauthorized person to bypass the PIN security screen. By interfering with the vehicle's internal communication during startup, an attacker can gain full access to the digital display and its functions without knowing the owner's PIN. This could lead to unauthorized access to user settings and vehicle information.

Technical details

An 'Incorrect Behavior Order' vulnerability exists in the boot sequence of the Indian Motorcycle Infotainment / Digital Round display. The system uses the presence of Wireless Control Module (WCM) traffic on the CAN bus as a proxy to determine if an immobilizer is installed. If an attacker silences WCM messages during the boot window (e.g., via a CAN bus-off attack), the system assumes no immobilizer is present and fails open, skipping the PIN entry requirement. This allows a physical attacker with access to the vehicle's internal network to access the fully unlocked user interface. Specific protocol details are currently withheld pending vendor remediation.

Affected products

  • Indian Motorcycle Scout Bobber + Tech 2025 2025 model year

Timeline

  • 2026-05-29: disclosed: CVE published to NVD

References

Related threats