Junglewise Threat Intelligence

CVE-2026-49324: Indian Motorcycle Scout Bobber resource consumption in WCM

CVE-2026-49324 · Severity: medium · CVSS 4.6 · Published 2026-05-29

Technologies: Indian Motorcycle Scout Bobber + Tech 2025. Vendors: Indian Motorcycle.

Executive brief

A vulnerability in the Wireless Control Module of the 2025 Indian Motorcycle Scout Bobber + Tech allows an attacker with physical access to the vehicle's internal network to permanently disable the motorcycle. By sending a small number of malicious messages, an attacker can trigger a security lockout that prevents the engine from starting. This lockout does not reset automatically and requires a professional dealer service to resolve, leading to significant operational disruption and repair costs.

Technical details

The Wireless Control Module (WCM) fails to properly restrict access to its immobilizer lockout counter, leading to a denial-of-service condition. An attacker with write access to the in-vehicle network (e.g., via the CAN bus) can send unauthenticated frames to increment the brute-force lockout counter. Because the counter lacks session binding and persists across power cycles, it can be intentionally exhausted to trigger a permanent lockout. Once the threshold is reached, the motorcycle is immobilized and cannot be started without dealer-level diagnostic tools to reset the module.

Affected products

  • Indian Motorcycle Scout Bobber + Tech 2025 2025 model year

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats