CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

My Eicher fleet API flaws exposed 676,000 trucks to takeover

Unauthenticated APIs in the Volvo-Eicher fleet platform let a researcher seize control of 676,000 commercial vehicles and their owners' data.

CarThreat Staff
Last updated: August 1, 2026 9:54 am
By
ctadmin
2 Min Read
My Eicher fleet API flaws exposed 676,000 trucks to takeover
SHARE

A researcher demonstrated that flaws in the My Eicher fleet platform could have handed attackers control of more than 676,000 commercial vehicles in India, along with the personal data of nearly 750,000 customers.

Eaton Zveare of Harness documented the vulnerabilities in a disclosure published July 27. My Eicher is the fleet management and GPS tracking system from VE Commercial Vehicles, the joint venture between the Volvo Group and Eicher Motors. Its customers include truck and bus operators across India.

Zveare found that walking up an API path on the platform’s website exposed a directory of hidden internal endpoints, many unauthenticated. Those endpoints returned lists of 748,000 customers, 174,000 users and 676,000 vehicles, plus 76,000 uploaded documents including Aadhaar cards and driving licenses. Another API exposed roughly 2.5 million one-time passwords going back to 2021.

By pulling the OTP for a target phone number and plugging it into the login flow, Zveare said he gained full control of any account, and by extension the entire fleet tied to it, which could span hundreds of trucks. A second method let him reset account passwords without alerting the owner.

The researcher reported the issues in November 2025. The primary vulnerability was closed that month, and the company remediated remaining concerns on July 28, days after the disclosure went public. VE Commercial Vehicles says there is no current threat to any customer or vehicle.

The case is a reminder that fleet telematics APIs can be as dangerous as vehicle ECUs. Exposed OTP stores, missing authentication and weak access controls turned a customer portal into a nationwide vehicle-takeover machine. OEMs building connected commercial fleets should treat internal APIs as attack surface and audit them for unauthenticated access before attackers do.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityData PrivacyTelematics Control Units (TCU)Vehicle SoftwareVulnerabilities
SOURCES:Eaton Zveare / My Eicher disclosureSecurityWeek
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Vehicles are getting their own offline AI brain thanks to FEV and Microsoft

By
ctadmin
July 12, 2026
Electric Vehicles

Fake plug-and-charge stations bill EV owners for stranger fills

By
ctadmin
August 9, 2026
Cybersecurity

Uber Invests $500M in Nuro Robotaxi Deal with Lucid Vehicles

By
ctadmin
June 12, 2026
Cybersecurity

Extortion group Helix claims a million files from Uber Freight

By
ctadmin
August 13, 2026
Cybersecurity

Automotive Cybersecurity Market Forecast Predicts $3.14 Billion by 2033 as Connected Vehicle Risks Mount

By
ctadmin
June 19, 2026
Cybersecurity

EV charger worm escapes a Tesla wall plug and hops to rival brands

By
ctadmin
August 22, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?