HomeSecurityElectric motorcycles and scooters face hacking risk

Electric motorcycles and scooters face hacking risk

Electric motorcycles from Zero Motorcycles and electric scooters from Yadea are affected by hacking vulnerabilities that, if exploited, could have physical impacts on the safety and security of riders. CISA recently published separate advisories about these vulnerabilities.

See also: Silk Typhoon: Hacker extradited to the US for “COVID espionage”

hacking
Electric motorcycles and scooters face hacking risk

Researchers at Bureau Veritas Cybersecurity have discovered that electric motorcycles from US company Zero Motorcycles are affected by a vulnerability that could allow an attacker to connect to a vehicle via Bluetooth. The vulnerability, tracked as CVE-2026-1354, affects firmware version 44 and earlier.

According to CISA, which classified the vulnerability as 'moderate severity' due to the high complexity of the attack, an attacker could gain unauthorized access to all Bluetooth functions and even upload malicious firmware to the motorcycle.

See also: TrustTrap operation reveals 16,800 fake domains

Electric motorcycles and scooters face hacking risk

Dinesh Shetty, director of security engineering at Bureau Veritas, said that while executing an attack may not be easy, a determined and well-equipped attacker could succeed. The attacker would need to be physically close to the targeted motorcycle, understand the pairing process, and remain nearby until the malicious firmware upload is complete. Once the attacker has uploaded malicious firmware, they can perform actions that could pose a serious security risk.

CISA said the vendor plans to release a firmware update in May and in the meantime has advised users to pair their motorcycle with their phone in a secure location where no one else can attempt to pair at the same time.

CISA recently issued a separate advisory about another potentially serious vulnerability affecting a two-wheeled vehicle, the T5 scooter manufactured by Chinese company Yadea. The vulnerability, tracked as CVE-2025-70994 and rated 'high severity', is a weak authentication issue that could allow an attacker to intercept legitimate transmissions from the key fob.

See also: UNC6783: New campaign to steal corporate data via BPO

Electric motorcycles and scooters face hacking risk

According to a tip from Ashen Chathuranga, the researcher who found the vulnerability, an attacker in close proximity to the targeted scooter can intercept a non-sensitive command — for example, a lock command — issued by the owner.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS