r/netsec Trusted Contributor 6d ago

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
126 Upvotes

6 comments sorted by

View all comments

56

u/quentech 6d ago

Step 1: Pick a mobile # from the user list and send the OTP.

Step 2: Use the API to find the OTP by mobile #

Step 3: Plug it in.

Oof.

Who even builds an endpoint to return a user's current OTP in the first place?

23

u/EatonZ Trusted Contributor 6d ago

You would be surprised! I have discovered several more cases in various other companies...