Vulnerabilità ed exploit · Attacco IoT / OT

Bluetooth Firmware Flaws Put Bikes and Scooters at Risk

The real problem is not theft. It is that Bluetooth update and command channels can become a path to persistent control of a vehicle, with safety impact that survives a simple disconnect. For riders, the standard assumption that wireless pairing is a convenience feature breaks here.

CISA has issued separate advisories for Zero Motorcycles and Yadea devices. Zero Motorcycles firmware version 44 and earlier is affected by CVE-2026-1354, which can let an attacker gain unauthorized access to Bluetooth functions and upload malicious firmware. Yadea scooters are affected by CVE-2025-70994, which can enable remote control and command replay.

The forward risk is broader than one model line. Any connected vehicle that trusts Bluetooth commands or firmware updates too easily can turn a nearby attacker into a persistent operator, and the compromise can outlast the original wireless session.

1 fonte · 28 apr

CVE-2026-1354

NVD KEV

CVSS 6.4 MEDIUM: zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. EPSS 0.1% (3º percentile).

CVE-2025-70994

NVD KEV

CVSS 7.3 HIGH: yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system.

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-29

Every edition of this story: Bluetooth Firmware Flaws Put Bikes and Scooters at Risk

Altro da oggi