A researcher demonstrated that flaws in the My Eicher fleet platform could have handed attackers control of more than 676,000 commercial vehicles in India, along with the personal data of nearly 750,000 customers.
Eaton Zveare of Harness documented the vulnerabilities in a disclosure published July 27. My Eicher is the fleet management and GPS tracking system from VE Commercial Vehicles, the joint venture between the Volvo Group and Eicher Motors. Its customers include truck and bus operators across India.
Zveare found that walking up an API path on the platform’s website exposed a directory of hidden internal endpoints, many unauthenticated. Those endpoints returned lists of 748,000 customers, 174,000 users and 676,000 vehicles, plus 76,000 uploaded documents including Aadhaar cards and driving licenses. Another API exposed roughly 2.5 million one-time passwords going back to 2021.
By pulling the OTP for a target phone number and plugging it into the login flow, Zveare said he gained full control of any account, and by extension the entire fleet tied to it, which could span hundreds of trucks. A second method let him reset account passwords without alerting the owner.
The researcher reported the issues in November 2025. The primary vulnerability was closed that month, and the company remediated remaining concerns on July 28, days after the disclosure went public. VE Commercial Vehicles says there is no current threat to any customer or vehicle.
The case is a reminder that fleet telematics APIs can be as dangerous as vehicle ECUs. Exposed OTP stores, missing authentication and weak access controls turned a customer portal into a nationwide vehicle-takeover machine. OEMs building connected commercial fleets should treat internal APIs as attack surface and audit them for unauthenticated access before attackers do.