Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

TL;DR AI
2 min readKey summary
Researchers found unauthenticated internal and admin APIs in VE Commercial Vehicles’ My Eicher platform.
The exposed endpoints leaked account and fleet data, OTP records, and other sensitive information.
Attackers could abuse the OTP-based login flow to take over accounts and potentially control users’ vehicles.
The flaw could expose personal and operational data across commercial fleets, affecting hundreds of vehicles.
