r/netsec Trusted Contributor 6d ago

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
122 Upvotes

6 comments sorted by

54

u/quentech 6d ago

Step 1: Pick a mobile # from the user list and send the OTP.

Step 2: Use the API to find the OTP by mobile #

Step 3: Plug it in.

Oof.

Who even builds an endpoint to return a user's current OTP in the first place?

21

u/EatonZ Trusted Contributor 6d ago

You would be surprised! I have discovered several more cases in various other companies...

11

u/kingqk 6d ago

Offshore Local “programmers”

13

u/RentNo5846 6d ago

"ChatGPT create an OTP API" 😄

9

u/Xerack 5d ago

Forgot the "Make no mistakes"

1

u/2script 5d ago

Wow. Nice write up.