CVE-2026-1354

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/04/2026
Last modified:
22/04/2026

Description

Zero Motorcycles firmware versions 44 and prior enable an attacker to <br /> forcibly pair a device with the motorcycle via Bluetooth. Once paired, <br /> an attacker can utilize over-the-air firmware updating functionality to <br /> potentially upload malicious firmware to the motorcycle. The motorcycle <br /> must first be in Bluetooth pairing mode, and the attacker must be in <br /> proximity of the vehicle and understand the full pairing process, to be <br /> able to pair their device with the vehicle. The attacker&amp;#39;s device must <br /> remain paired with and in proximity of the motorcycle for the entire <br /> duration of the firmware update.