Executive brief
A security vulnerability in the 2025 Indian Motorcycle Scout Bobber + Tech model could allow an unauthorized person to discover the owner's secret unlock PIN. By monitoring the motorcycle's internal communication network while the owner enters their PIN, an attacker can mathematically calculate the code. This bypasses the primary security control used to prevent unauthorized use of the vehicle.
Technical details
The Wireless Control Module (WCM) and Infotainment Digital Round display in the 2025 Indian Motorcycle Scout Bobber + Tech utilize a weak authentication mechanism that lacks proper cryptographic challenge-response protocols. The system computes authentication responses using non-cryptographic operations, making the user-set unlock PIN mathematically derivable from a single captured exchange. An attacker with physical or adjacent access to the in-vehicle network (such as the CAN bus) can passively monitor the traffic to recover the PIN, leading to a complete bypass of the vehicle's primary user-authentication control. Specific protocol details are currently withheld pending a fix from the vendor.
Affected products
- Indian Motorcycle Scout Bobber + Tech 2025 2025 model year
Timeline
- 2026-05-29: disclosed: CVE published to the NVD dataset