Switch language한국어
Back to the list

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

TL;DR AI

Key summary

2 min read
  1. Researchers found unauthenticated internal and admin APIs in VE Commercial Vehicles’ My Eicher platform.

  2. The exposed endpoints leaked account and fleet data, OTP records, and other sensitive information.

  3. Attackers could abuse the OTP-based login flow to take over accounts and potentially control users’ vehicles.

  4. The flaw could expose personal and operational data across commercial fleets, affecting hundreds of vehicles.

Read the original