A security vulnerability was identified in the My Eicher fleet management system, operated by VE Commercial Vehicles, a joint venture of Volvo Group and Eicher Motors. This platform is used by Indian commercial vehicle customers to manage their fleets.
The vulnerability resided in the platform's APIs, which allowed for the discovery of hidden, unauthenticated internal and administrative APIs. Exploiting these APIs granted high-level system access and facilitated account takeover. This meant an attacker could gain control over a person's or company's entire fleet of vehicles.
The flaw exposed a significant amount of data. As of November 2024, the platform had 275,000 registered vehicles and 115,000 customers. However, API data indicated exposure for 748,000 customers, 174,000 users, 186,000 persons, 676,000 vehicles, and 76,000 documents, including Aadhaar cards and driving licenses. The discrepancy in numbers between announced registrations and API-pulled data is unclear.
The vulnerabilities specifically impacted commercial vehicles and customers within India. The My Eicher platform enables features such as real-time vehicle tracking, live gauge cluster viewing, and geofencing for fleets of trucks and buses.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A vulnerability was discovered in the My Eicher fleet management platform, a joint venture between Volvo Group and Eicher Motors, which allowed access to hidden administrative APIs. This flaw enabled account takeover and exposed data for hundreds of thousands of customers and vehicles in India. The vulnerability could have allowed unauthorized control over entire commercial vehicle fleets.