Bluetooth Firmware Flaws Put Bikes and Scooters at Risk
The real problem is not theft. It is that Bluetooth update and command channels can become a path to persistent control of a vehicle, with safety impact that survives a simple disconnect. For riders, the standard assumption that wireless pairing is a convenience feature breaks here.
CISA has issued separate advisories for Zero Motorcycles and Yadea devices. Zero Motorcycles firmware version 44 and earlier is affected by CVE-2026-1354, which can let an attacker gain unauthorized access to Bluetooth functions and upload malicious firmware. Yadea scooters are affected by CVE-2025-70994, which can enable remote control and command replay.
The forward risk is broader than one model line. Any connected vehicle that trusts Bluetooth commands or firmware updates too easily can turn a nearby attacker into a persistent operator, and the compromise can outlast the original wireless session.