PT-2026-34184 · Zero Motorcycles · Zero Motorcycles Firmware

Persephone Karnstein

·

Published

2026-04-21

·

Updated

2026-04-26

·

CVE-2026-1354

CVSS v3.1

6.4

Medium

VectorAV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zero Motorcycles firmware versions 44 and prior
Description An issue in the Bluetooth pairing process allows an attacker in close proximity to forcibly pair a device with the motorcycle while it is in pairing mode. Once paired, the attacker can use the over-the-air firmware updating functionality to upload malicious firmware to the vehicle. Real-world incidents have occurred where this was exploited to compromise vehicle functions.
Recommendations Update firmware to a version later than 44.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1354

Affected Products

Zero Motorcycles Firmware