← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Vulnerability in Volvo/Eicher's My Eicher fleet platform allowed account takeover and data exposure

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Vulnerability found in My Eicher fleet management platform APIs.
  • Allowed discovery of hidden, unauthenticated internal/admin APIs.
  • Enabled high-level access, including account takeover.
  • Exposed data for 748k customers, 676k vehicles, and 76k documents.

Vulnerability in My Eicher Platform

A security vulnerability was identified in the My Eicher fleet management system, operated by VE Commercial Vehicles, a joint venture of Volvo Group and Eicher Motors. This platform is used by Indian commercial vehicle customers to manage their fleets.

API Flaw Led to Account Takeover

The vulnerability resided in the platform's APIs, which allowed for the discovery of hidden, unauthenticated internal and administrative APIs. Exploiting these APIs granted high-level system access and facilitated account takeover. This meant an attacker could gain control over a person's or company's entire fleet of vehicles.

Extensive Data Exposure

The flaw exposed a significant amount of data. As of November 2024, the platform had 275,000 registered vehicles and 115,000 customers. However, API data indicated exposure for 748,000 customers, 174,000 users, 186,000 persons, 676,000 vehicles, and 76,000 documents, including Aadhaar cards and driving licenses. The discrepancy in numbers between announced registrations and API-pulled data is unclear.

Impact on Commercial Vehicles in India

The vulnerabilities specifically impacted commercial vehicles and customers within India. The My Eicher platform enables features such as real-time vehicle tracking, live gauge cluster viewing, and geofencing for fleets of trucks and buses.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A vulnerability was discovered in the My Eicher fleet management platform, a joint venture between Volvo Group and Eicher Motors, which allowed access to hidden administrative APIs. This flaw enabled account takeover and exposed data for hundreds of thousands of customers and vehicles in India. The vulnerability could have allowed unauthorized control over entire commercial vehicle fleets.