Carmaker Portal Flaw Could Let Hackers Unlock Cars, Steal Data
ID: efdc2c55-ffb0-5317-aa9e-0eb2311bf04f
STIX ID: report--efdc2c55-ffb0-5317-aa9e-0eb2311bf04f
Feed Name: HackRead
Threat Score
A security researcher discovered and disclosed an authentication flaw in a major automaker’s dealer portal that allowed creation of an elevated “national administrator” account, exposing thousands of customers’ personal and financial data, revealing real-time vehicle locations, and enabling remote actions such as unlocking cars using VINs or owner names; the vendor patched the issue about a week after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
