Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
4 hours ago
- My Eicher, a fleet management system by Volvo/Eicher joint venture, was found to have unauthenticated internal APIs.
- The vulnerability allowed enumeration of 748k customers, 174k users, 676k vehicles, and 2.5 million OTPs.
- Attackers could perform account takeover by intercepting OTPs or updating passwords without user notification.
- Exposed sensitive data included 76k documents such as Aadhaar cards and driving licenses.
- The vulnerability was reported in November 2025 and fixed by November 20, 2025, after multiple follow-ups.
- The hack affected only Indian commercial vehicle customers, with the disclosure published in July 2026.