CVE-2026-1354
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/04/2026
Last modified:
22/04/2026
Description
Zero Motorcycles firmware versions 44 and prior enable an attacker to <br />
forcibly pair a device with the motorcycle via Bluetooth. Once paired, <br />
an attacker can utilize over-the-air firmware updating functionality to <br />
potentially upload malicious firmware to the motorcycle. The motorcycle <br />
must first be in Bluetooth pairing mode, and the attacker must be in <br />
proximity of the vehicle and understand the full pairing process, to be <br />
able to pair their device with the vehicle. The attacker&#39;s device must <br />
remain paired with and in proximity of the motorcycle for the entire <br />
duration of the firmware update.
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM
Base Score 3.x
6.40
Severity 3.x
MEDIUM



