CVE-2026-49322

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital Round display computes its response using a non-cryptographic operation rather than a cryptographic challenge-response, so the PIN is mathematically derivable from one captured exchange, defeating the motorcycle's primary user-authentication control. Specific protocol details have been withheld pending vendor remediation.
Configurations

No configuration.

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Autenticación débil en el Módulo de Control Inalámbrico (WCM) de la motocicleta Indian Motorcycle Scout Bobber + Tech año modelo 2025 permite a un atacante de red adyacente con acceso de lectura a la red del vehículo recuperar el PIN de desbloqueo establecido por el usuario observando pasivamente un único intercambio de autenticación de PIN. La pantalla Infotainment Digital Round calcula su respuesta utilizando una operación no criptográfica en lugar de un desafío-respuesta criptográfico, por lo que el PIN es matemáticamente derivable de un intercambio capturado, derrotando el control principal de autenticación de usuario de la motocicleta. Los detalles específicos del protocolo han sido retenidos a la espera de la remediación del proveedor.

29 May 2026, 15:16

Type Values Removed Values Added
References
  • {'url': 'https://cwe.mitre.org/data/definitions/1390.html', 'source': 'cve@asrg.io'}
  • () https://www.asrg.io/security-advisories/cve-2026-49322-indian-scout-infotainment-wcm-weak-authentication -

29 May 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 08:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-49322

Mitre link : CVE-2026-49322

CVE.ORG link : CVE-2026-49322


JSON object : View

Products Affected

No product.

CWE
CWE-294

Authentication Bypass by Capture-replay

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-1390

Weak Authentication