logo

Web to Wheels: Tesla Password Insecurity Exposes Cars, Drivers

ID: f93b3fe2-cb97-5b0c-8627-66a880819cd8

STIX ID: report--f93b3fe2-cb97-5b0c-8627-66a880819cd8

Feed Name: Security Ledger

Threat Score
55/100

Date Published: 2014-03-31

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Research presented at Black Hat Asia found that Tesla Model S relies on a weak six-character PIN and allows unlimited password retries in its mobile app and website, enabling brute-force compromise; additionally, web vulnerabilities, exposed third-party API credentials, and potential social-engineering of support staff could let attackers track vehicles and control remote functions (lock/unlock), though driving theft is unlikely without the key fob. The researcher recommends stronger authentication (longer passwords or MFA) and sandboxing third-party apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.