RC RANDOM CHAOS

Exposed admin APIs handed full control of 676k trucks on Volvo-Eicher fleet platform

· via Hacker News

Original source

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

Hacker News →

A researcher found that My Eicher — the telematics and fleet-tracking platform run by VE Commercial Vehicles, a Volvo Group and Eicher Motors joint venture serving Indian commercial fleets — left a family of internal APIs completely exposed. By walking up an API path visible in the site’s homepage JavaScript, they landed on an unauthenticated directory of user-management endpoints. Those endpoints dumped the full account base: figures pulled from the API included 748k customers, 174k users, and 676k vehicles, plus 76k uploaded ID documents such as Aadhaar cards and driving licenses. Stored passwords were returned too, though they were encrypted and unusable.

The real break was an endpoint that exposed roughly 2.5 million one-time passwords going back to 2021, along with lookups to fetch the current OTP for any given mobile number. That collapsed authentication entirely: pick any account from the exposed user list, trigger an OTP, read it back through the API, and log in. A second path let an attacker rewrite an account’s password directly. Either method granted full control of a victim’s fleet — live GPS tracking, geofences, and the driver-facing gauge cluster for potentially hundreds of vehicles per account.

The severity here is less a clever exploit than a basic access-control failure on infrastructure tied to real-world vehicles and government ID data. VECV was slow to engage: reported November 3, 2025, the core flaw was quietly fixed by November 20 after repeated follow-ups, but the researcher says he never got anyone to look into his remaining concerns and eventually gave up. The exposure affected only India-based commercial vehicles and customers.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.