CyberRota
← Ana sayfaya dön

CVE-2026-49318

LOW · CVSS 2.4 EPSS %0.14

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-29T14:16:32.780 · Çekilme zamanı: 2026-06-28T12:00:34.476996+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-49318
Severity
LOW
CVSS
2.4
EPSS
%0.14

Orijinal NVD Açıklaması

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window — for example via a separately tracked CAN bus-off technique — can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation.