Cybersecurity researchers have uncovered serious software vulnerabilities in Zero Motorcycles and Yadea electric scooters, enabling hackers to remotely control key systems. The flaws range from tracking location to manipulating throttle and brakes, posing significant safety risks for riders in Saudi Arabia, the UAE, and beyond.
In a concerning development for electric motorcycle and scooter enthusiasts, cybersecurity researchers have discovered critical vulnerabilities in Zero Motorcycles and Yadea scooters. These flaws allow hackers to remotely access and control vehicle systems, potentially leading to theft or dangerous accidents. The findings, reported by RideApart, highlight the growing importance of cybersecurity in connected vehicles.
What are the security flaws?
The vulnerabilities exist in the smartphone apps used to control Zero and Yadea vehicles. Researchers from Pen Test Partners, a specialized penetration testing firm, identified weaknesses in the communication protocols between the app and the vehicle. For Zero Motorcycles, the flaw allows attackers to bypass authentication, access user data (including GPS location), and send commands such as starting or stopping the engine. For Yadea scooters, the flaws are more severe: hackers can remotely control the throttle and brakes, potentially causing accidents. They could also start the scooter without a key.
Who discovered these vulnerabilities?
The security holes were uncovered by Pen Test Partners, a UK-based cybersecurity firm. The researchers responsibly disclosed the vulnerabilities to both manufacturers before publishing their findings, giving them time to develop fixes.
Have security updates been released?
Zero Motorcycles has released a software update for its app that patches the vulnerabilities. The company urges all users to update immediately. Yadea has not yet issued a fix but is working on a solution. Experts advise Yadea users to temporarily disable wireless connectivity (Bluetooth/Wi-Fi) on their scooters until an update is available.
How can you protect your bike?
- Update the app: Ensure your motorcycle or scooter app is always up to date.
- Use strong passwords: Create unique, complex passwords for your app account.
- Enable two-factor authentication (2FA): If supported, activate 2FA for an extra layer of security.
- Avoid public Wi-Fi: Do not use the app on unsecured public networks.
- Monitor for unusual activity: Watch for unexpected engine starts or other anomalies in the app.
When will updates reach the Gulf market?
Both companies have not specified release dates for the Gulf region, but updates are expected to be available globally via app stores. Riders in Saudi Arabia and the UAE should regularly check their app store for updates. Given the region’s hot climate, which can affect battery and electronics, keeping software updated is especially important for reliability and safety.
Key facts at a glance
- Affected vehicles: Zero Motorcycles and Yadea Scooters
- Vulnerability type: Smartphone app hacking via communication protocol flaws
- Greatest risk: Remote control of throttle and brakes (Yadea)
- Discoverer: Pen Test Partners
- Update status: Zero: released; Yadea: in development
- Recommended action: Update app immediately; disable wireless on Yadea temporarily
Frequently asked questions
Can my Zero motorcycle be hacked?
Yes, vulnerabilities were found in the Zero app that allow hackers to bypass authentication, access your data, and control the bike. However, Zero has released a security update, so update your app immediately to stay protected.
How do Yadea’s flaws compare to Zero’s?
Yadea’s flaws are more dangerous because they enable remote control of throttle and brakes, which could lead to crashes. Zero’s flaws primarily involve data access and engine start/stop.
How can I protect my Yadea scooter until the update arrives?
Experts recommend disabling Bluetooth and Wi-Fi on the scooter temporarily, and only using the app when necessary. Also, change your app password to a strong one.
Are these vulnerabilities present in older models?
The report does not specify model years, but the vulnerabilities are tied to the smartphone app, so any vehicle using the affected app versions could be at risk. Check with your dealer for specific model information.
Frequently Asked Questions
Can my Zero motorcycle be hacked?
Yes, vulnerabilities were found in the Zero app that allow hackers to bypass authentication, access your data, and control the bike. However, Zero has released a security update, so update your app immediately to stay protected.
How do Yadea's flaws compare to Zero's?
Yadea's flaws are more dangerous because they enable remote control of throttle and brakes, which could lead to crashes. Zero's flaws primarily involve data access and engine start/stop.
How can I protect my Yadea scooter until the update arrives?
Experts recommend disabling Bluetooth and Wi-Fi on the scooter temporarily, and only using the app when necessary. Also, change your app password to a strong one.
Are these vulnerabilities present in older models?
The report does not specify model years, but the vulnerabilities are tied to the smartphone app, so any vehicle using the affected app versions could be at risk. Check with your dealer for specific model information.
Sources
- RideApart — Zero Motorcycles and Yadea Scooters Both Have Software Security Vulnerabilities
