PT-2026-44852 · Indian Motorcycle · Scout Bobber + Tech 2025

CVE-2026-49318

·

Published

2026-05-29

·

Updated

2026-06-27

CVSS v3.1

2.4

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Indian Motorcycle Scout Bobber + Tech 2025 model year
Description An incorrect behavior order in the Infotainment / Digital Round display allows an attacker on an adjacent network to bypass the PIN entry screen. The system uses the presence of Wireless Control Module (WCM) traffic during the boot window as a proxy to determine if an immobilizer is fitted. If no WCM messages are detected, the system skips the PIN entry and displays the normal user interface. An attacker can achieve a fully unlocked state by silencing the WCM during the boot window, for instance, by using a CAN bus-off technique, which is a method used to force a CAN node into an error state to stop it from communicating.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49318

Affected Products

Scout Bobber + Tech 2025