Security vulnerability allows hackers to take control of customers' vehicles

HẠO THIÊN (T/H) |

A security expert discovered a vulnerability in the dealer portal of a major automaker, which could expose personal data and vehicle information.

Phat hien lo hong nghiem trong trong cong thong tin danh cho dai ly cua mot hang san xuat oto. Do hoa: Hao Thien
Severe security vulnerability discovered in the portal for dealers of an auto manufacturer. Graphics: Hao Thien

Eaton Zveare - a security expert at software company Harness - has just discovered a serious vulnerability in the dealership portal of a car manufacturer, which exposed personal data and customer vehicle information, and could allow hackers to remotely control the car, according to Techcrunch.

Eaton Zveare said the vulnerability allows the creation of an administrative account with unlimited access to the automaker's centralized web system. Bad guys can view personal and financial data, track vehicle location, and even activate remote control features such as unlocking.

Zveare discovered the error earlier this year in a personal project. Although it is difficult to find, once exploited, this error allows the full registration step to create a national administrative account. The reason is that the error code was loaded immediately upon opening the login page, allowing editing to pass the authentication mechanism. Although the automaker was not named for security reasons, the company said that there were no signs of a vulnerability being exploited before.

With access, Zveare can access data from more than 1,000 dealers in the US, looking up vehicle and owner information with just a name or VIN. This expert experimented on a friend's car and found that the system only required oral confirmation to transfer account ownership.

The portal also allows for a one-time login to access the system of other agents, and has the ability to impersonate another user without a password. This is similar to the defect that was discovered on Toyota's system in 2023.

Inside the system, Zveare finds identification data, some financial information, the ability to track the real-time location of the rental vehicle, a service vehicle or a vehicle being transported, and even the option to cancel the transportation order.

Currently, the automaker has fixed the error when receiving the report in February 2025. Zveare warns: Just two simple API vulnerabilities are enough to break down security doors.

HẠO THIÊN (T/H)
RELATED NEWS

Google Gemini reveals security weaknesses when connecting to physical devices

|

A research team has just shown how hackers can deceive Google Gemini, allowing this AI to automatically control smart home devices over appointments.

ABBANK introduces super-fast, secure digital banking app

|

An Binh Commercial Joint Stock Bank (ABBANK) has just officially launched a new generation digital banking platform for individual customers called ABBANK to replace the AB Ditizen application, helping customers easily manage their finances and make effective spending decisions, meeting the financial needs of individuals, business households and families.

The new iOS 26 beta allows Wi-Fi security testing right on iPhone

|

The new iOS 26 beta brings many upgrades in interface, weak battery warnings on Dynamic Island and allows Wi-Fi security testing right on the iPhone.

Improving human resources from the internal strength of enterprises

|

Good human resources and the application of science and technology in production are factors that create a foundation for businesses to develop sustainably.

Many unusual things at the pig farm blocking the highway in Ha Tinh

|

Ha Tinh - The Provincial Inspectorate has just issued a conclusion pointing out unusual and violations related to the pig farm project blocking the highway.

Behind the parade is the silent sacrifice of teachers

|

Hanoi - Behind the solemn and powerful parade and march (A80) that are being practiced day and night is the silent sacrifice of the teachers.

The marine parade formation practices phase 2, ready for the September 2 grand ceremony

|

The marine parade force is actively practicing phase 2 according to plan, ready for the national big festival.

Human resource development in the digital transformation era

|

In Vietnam, digital transformation and green growth are no longer a slogan but a vital requirement. However, human resources, especially the workforce in enterprises, are facing unprecedented pressure.

Google Gemini reveals security weaknesses when connecting to physical devices

Cát Tiên (THEO hindustantimes) |

A research team has just shown how hackers can deceive Google Gemini, allowing this AI to automatically control smart home devices over appointments.

ABBANK introduces super-fast, secure digital banking app

Đinh Hương |

An Binh Commercial Joint Stock Bank (ABBANK) has just officially launched a new generation digital banking platform for individual customers called ABBANK to replace the AB Ditizen application, helping customers easily manage their finances and make effective spending decisions, meeting the financial needs of individuals, business households and families.

The new iOS 26 beta allows Wi-Fi security testing right on iPhone

Cát Tiên (THEO hindustantimes) |

The new iOS 26 beta brings many upgrades in interface, weak battery warnings on Dynamic Island and allows Wi-Fi security testing right on the iPhone.