CVE-2026-1354
CVSS 6.4 MEDIUM: zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. EPSS 0.1% (3º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
The real problem is not theft. It is that Bluetooth update and command channels can become a path to persistent control of a vehicle, with safety impact that survives a simple disconnect. For riders, the standard assumption that wireless pairing is a convenience feature breaks here.
CISA has issued separate advisories for Zero Motorcycles and Yadea devices. Zero Motorcycles firmware version 44 and earlier is affected by CVE-2026-1354, which can let an attacker gain unauthorized access to Bluetooth functions and upload malicious firmware. Yadea scooters are affected by CVE-2025-70994, which can enable remote control and command replay.
The forward risk is broader than one model line. Any connected vehicle that trusts Bluetooth commands or firmware updates too easily can turn a nearby attacker into a persistent operator, and the compromise can outlast the original wireless session.
1 fonte · 28 apr
CVSS 6.4 MEDIUM: zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. EPSS 0.1% (3º percentile).
CVSS 7.3 HIGH: yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system.
SecurityWeek
Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety
Vulnerabilities in Zero Motorcycles electric motorcycles and Yadea electric scooters can pose physical security and safety risks.
originalePart of the PlainSec briefing for 2026-04-29
Every edition of this story: Bluetooth Firmware Flaws Put Bikes and Scooters at Risk