IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Zero Motorcycles Firmware (Update A)

MEDIUM
CVSS 6.4
Date 2026-06-23T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to pair via Bluetooth with a motorcycle, gaining unauthorized access to all Bluetooth functions, including changing the firmware.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-1354 6.4 medium
Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air firmware updating functionality to potentially upload malicious firmware to the motorcycle. The motorcycle must first be in Bluetooth pairing mode, and the attacker must be in proximity of the vehicle and understand the full pairing process, to be able to pair their device with the vehicle. The attacker's device must remain paired with and in proximity of the motorcycle for the entire duration of the firmware update.

// Remediations (1)

Mitigation: Zero Motorcycles has investigated this report and cautions users to pair their mobile device to thei
Zero Motorcycles has investigated this report and cautions users to pair their mobile device to their vehicle in a safe location where they can be sure no one else will try to pair at the same time. Once initiated, complete the full pairing process and confirm it is successful. Store physical keys in a secure location and do not leave the bike unattended with the key in the "ON" position. Zero Motorcycles has addressed this issue in a firmware update that is available on their FOTA platform and can be obtained by using the mobile app or by visiting an authorized Zero Motorcycles dealership. Zero Motorcycles recommends all users update the firmware to the latest available version.

// References