HeadlinesBriefing favicon HeadlinesBriefing.com

Volvo/Eicher Fleet Platform Vulnerability

Hacker News •
×

A significant vulnerability has been discovered in the "My Eicher" fleet management platform, used by commercial vehicle customers in India. This platform, a joint venture between the Volvo Group and Eicher Motors, allows users to track and manage their fleets. The vulnerability in its APIs enabled the discovery of hidden, unauthenticated internal endpoints. These could be exploited to gain high-level system access, including account takeover. This takeover allowed control over a user's entire fleet, potentially comprising hundreds of vehicles. As of November 2024, the platform registered 275k vehicles and 115k customers. The exploit could expose sensitive data, including 76k documents like Aadhaar cards and driving licenses.

The vulnerability allowed for the discovery of unauthenticated APIs, leading to the retrieval of large lists of customers, users, and persons. Crucially, an API was found that exposed a history of 2.5 million OTPs, facilitating account takeover by intercepting and using these codes. A secondary method involved using password reset APIs. The researcher reported the vulnerability in November 2025, and the primary exploit was fixed by November 20, 2025.