Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-1354

Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/04/2026
Última modificación:
22/04/2026

Descripción

*** Pendiente de traducción *** Zero Motorcycles firmware versions 44 and prior enable an attacker to <br /> forcibly pair a device with the motorcycle via Bluetooth. Once paired, <br /> an attacker can utilize over-the-air firmware updating functionality to <br /> potentially upload malicious firmware to the motorcycle. The motorcycle <br /> must first be in Bluetooth pairing mode, and the attacker must be in <br /> proximity of the vehicle and understand the full pairing process, to be <br /> able to pair their device with the vehicle. The attacker&amp;#39;s device must <br /> remain paired with and in proximity of the motorcycle for the entire <br /> duration of the firmware update.