Junglewise Threat Intelligence

CVE-2026-49325: Indian Motorcycle Scout Bobber anti-theft bypass in WCM wiring

CVE-2026-49325 · Severity: medium · CVSS 4.6 · Published 2026-05-29

Technologies: Indian Motorcycle Scout Bobber + Tech 2025. Vendors: Indian Motorcycle.

Executive brief

A security flaw in the 2025 Indian Motorcycle Scout Bobber + Tech allows an attacker with physical access to bypass the vehicle's anti-theft system. By manipulating specific wiring, an unauthorized individual can keep the motorcycle operational without entering the required security PIN. This vulnerability significantly increases the risk of vehicle theft by neutralizing the electronic ignition lockout.

Technical details

The vulnerability exists in the bike-shutdown control logic between the Wireless Control Module (WCM) and a peer ECU. The WCM signals a shutdown via a falling-edge voltage transition on a dedicated wire pair; however, the receiving ECU fails to distinguish between a legitimate shutdown signal and an open-circuit condition caused by wire interruption. A physical attacker can exploit this by accessing the WCM wiring harness and disconnecting the relevant wires, preventing the anti-theft shutdown from triggering even if a valid PIN is never provided. This is classified as improper handling of physical conditions (CWE-1384).

Affected products

  • Indian Motorcycle Scout Bobber + Tech 2025 2025 model year

Timeline

  • 2026-05-29: disclosed: Vulnerability published in NVD dataset

References

Related threats