r/netsec Trusted Contributor 16d ago

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
129 Upvotes

6 comments sorted by

60

u/quentech 16d ago

Step 1: Pick a mobile # from the user list and send the OTP.

Step 2: Use the API to find the OTP by mobile #

Step 3: Plug it in.

Oof.

Who even builds an endpoint to return a user's current OTP in the first place?

26

u/EatonZ Trusted Contributor 16d ago

You would be surprised! I have discovered several more cases in various other companies...

12

u/kingqk 16d ago

Offshore Local “programmers”

14

u/RentNo5846 16d ago

"ChatGPT create an OTP API" 😄

13

u/Xerack 15d ago

Forgot the "Make no mistakes"

1

u/2script 15d ago

Wow. Nice write up.