CVE-2026-49316

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection technique against a periodic WCM transmission, the attacker drives the WCM CAN controller's transmit error counter past the bus-off threshold, after which the WCM stops transmitting all messages, including the shutdown command. Peer ECUs do not interpret WCM silence as a security event and continue normal operation, allowing the motorcycle to be operated despite the immobilizer never having been unlocked. Specific protocol details have been withheld pending vendor remediation.
Configurations

No configuration.

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Violación del comportamiento esperado en la red interna del vehículo del modelo Indian Motorcycle Scout Bobber + Tech año 2025 permite a un atacante de red adyacente eludir el apagado antirrobo de la motocicleta forzando el Módulo de Control Inalámbrico (WCM) al estado de bus-off de CAN. Utilizando una técnica conocida de inyección de tramas de error CAN contra una transmisión periódica del WCM, el atacante lleva el contador de errores de transmisión del controlador CAN del WCM más allá del umbral de bus-off, después de lo cual el WCM deja de transmitir todos los mensajes, incluyendo el comando de apagado. Las ECU pares no interpretan el silencio del WCM como un evento de seguridad y continúan su funcionamiento normal, permitiendo que la motocicleta sea operada a pesar de que el inmovilizador nunca haya sido desbloqueado. Los detalles específicos del protocolo han sido retenidos a la espera de la remediación del proveedor.

29 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 14:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-49316

Mitre link : CVE-2026-49316

CVE.ORG link : CVE-2026-49316


JSON object : View

Products Affected

No product.

CWE
CWE-440

Expected Behavior Violation

CWE-693

Protection Mechanism Failure

CWE-754

Improper Check for Unusual or Exceptional Conditions