Executive brief
A security flaw in the 2025 Indian Motorcycle Scout Bobber + Tech model allows an attacker to bypass the vehicle's anti-theft immobilizer. By monitoring the communication between internal electronic modules, an attacker can recover a secret key used to authorize engine starts. This could allow an unauthorized person to start the motorcycle's engine and drive it away without the legitimate key or wireless module present.
Technical details
The vulnerability stems from a weak authentication mechanism between the Wireless Control Module (WCM) and the Engine Control Module (ECM). The WCM utilizes a reversible, non-cryptographic operation for its seed/key exchange rather than a robust cryptographic challenge-response. An attacker with physical or adjacent access to the in-vehicle network can passively observe a single exchange to reconstruct the persistent ECM immobilizer secret. Once this secret is obtained, the attacker can independently authenticate to the ECM, effectively defeating the immobilizer and enabling unauthorized engine ignition. Specific protocol details are currently withheld by the vendor.
Affected products
- Indian Motorcycle Scout Bobber + Tech 2025 model year
Timeline
- 2026-05-29: advisory: Vulnerability published in NVD