CVE-2026-1354
Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/04/2026
Última modificación:
22/04/2026
Descripción
*** Pendiente de traducción *** Zero Motorcycles firmware versions 44 and prior enable an attacker to <br />
forcibly pair a device with the motorcycle via Bluetooth. Once paired, <br />
an attacker can utilize over-the-air firmware updating functionality to <br />
potentially upload malicious firmware to the motorcycle. The motorcycle <br />
must first be in Bluetooth pairing mode, and the attacker must be in <br />
proximity of the vehicle and understand the full pairing process, to be <br />
able to pair their device with the vehicle. The attacker&#39;s device must <br />
remain paired with and in proximity of the motorcycle for the entire <br />
duration of the firmware update.
Impacto
Puntuación base 4.0
5.90
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.40
Gravedad 3.x
MEDIA



