Back Escudodigital New flaw lets hackers remotely control electric motorcycle | DigitalShield
Researchers from the firm Bureau Veritas Cybersecurity have discovered that the electric motorcycles from the American company Zero Motorcycles have a vulnerability that could allow an attacker to connect to the vehicle via Bluetooth.
The vulnerability, identified as CVE-2026-1354 , affects firmware version 44 and earlier. CISA has classified the flaw as "medium severity."
A technically knowledgeable threat actor could gain access to all Bluetooth functions, including the ability to upload malicious firmware to the bike.
However, the hack would only be possible, obviously, if the hacker is physically within a reasonable distance of the vehicle and remains nearby until the malicious code upload is complete .
Dinesh Shetty, director of security engineering at Bureau Veritas, acknowledged to Security Week that carrying out such an incident is not easy, but a motivated attacker with the necessary resources could achieve it.
"Zero motorcycles have a Bluetooth pairing mode that activates by holding the Mode button for five seconds, or if the bike has never been paired before. During that time, the key exchange does not verify who is connecting," warns the expert.
"An attacker within Bluetooth range could connect and pair their own device with the bike, and it would accept it as a legitimate connection. Once paired, the device is perceived as trusted and can use the firmware update channel to send a modified firmware image to the motorcycle," adds Shetty.
Once this updated software is present in the hacked unit, the cybercriminal has acquired the ability to perform actions with a serious risk to motorcyclist safety .
"The motorcycle's main microcontroller controls critical safety functions such as torque, regenerative braking, contactors that supply power to the motor, and battery management. If custom firmware is installed, any of these parameters can be modified," warns the head of Bureau Veritas Cybersecurity.
These potential modifications would be fatal at high speeds. "Throttle response could be altered, braking interfered with, or even thermal safety measures of the battery manipulated," Shetty indicates, also commenting that "the board also has access to a cellular modem for GPS and telemetry, which in theory could be used for remote control. " It's not changing the color of the instrument panel; it's firmware that governs the physical behavior of the vehicle," he concludes.
CISA has indicated that the provider plans to release a firmware update in May . Until it arrives, the agency has advised users to connect their bike to their phone in a secure location where no one else can attempt to make the connection at the same time .
Researchers from the firm Bureau Veritas Cybersecurity have discovered that the electric motorcycles from the American company Zero Motorcycles have a vulnerability that could allow an attacker to connect to the vehicle via Bluetooth.
The vulnerability, identified as CVE-2026-1354 , affects firmware version 44 and earlier. CISA has classified the flaw as "medium severity."
A technically knowledgeable threat actor could gain access to all Bluetooth functions, including the ability to upload malicious firmware to the bike.
However, the hack would only be possible, obviously, if the hacker is physically within a reasonable distance of the vehicle and remains nearby until the malicious code upload is complete .
Dinesh Shetty, director of security engineering at Bureau Veritas, acknowledged to Security Week that carrying out such an incident is not easy, but a motivated attacker with the necessary resources could achieve it.
"Zero motorcycles have a Bluetooth pairing mode that activates by holding the Mode button for five seconds, or if the bike has never been paired before. During that time, the key exchange does not verify who is connecting," warns the expert.
"An attacker within Bluetooth range could connect and pair their own device with the bike, and it would accept it as a legitimate connection. Once paired, the device is perceived as trusted and can use the firmware update channel to send a modified firmware image to the motorcycle," adds Shetty.
Once this updated software is present in the hacked unit, the cybercriminal has acquired the ability to perform actions with a serious risk to motorcyclist safety .
"The motorcycle's main microcontroller controls critical safety functions such as torque, regenerative braking, contactors that supply power to the motor, and battery management. If custom firmware is installed, any of these parameters can be modified," warns the head of Bureau Veritas Cybersecurity.
These potential modifications would be fatal at high speeds. "Throttle response could be altered, braking interfered with, or even thermal safety measures of the battery manipulated," Shetty indicates, also commenting that "the board also has access to a cellular modem for GPS and telemetry, which in theory could be used for remote control. " It's not changing the color of the instrument panel; it's firmware that governs the physical behavior of the vehicle," he concludes.
CISA has indicated that the provider plans to release a firmware update in May . Until it arrives, the agency has advised users to connect their bike to their phone in a secure location where no one else can attempt to make the connection at the same time .
Become a premium member for free!
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
