Kia dealer portal flaw could let attackers hack millions of cars
ID: 06aa790b-695a-5524-af29-7f4b09381b4c
STIX ID: report--06aa790b-695a-5524-af29-7f4b09381b4c
Feed Name: Bleeping Computer
Researchers disclosed critical flaws in Kia's dealer web portal that could allow someone with a registered dealer account to generate access tokens, pull vehicle owner PII (name, email, phone, address), add themselves as a second user, and remotely control millions of Kia vehicles made after 2013 (lock/unlock/start/locate/honk). The team built a demonstration showing an attacker could act within ~30 seconds; the issues were reportedly fixed and no evidence of malicious exploitation was found.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
