Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

eaton-works.com

86 points by EatonZ 6 hours ago


darknavi - 3 hours ago

> November 3, 2025: Reported.

> November 10, 2025: No response, followed up.

> November 17, 2025: No response, followed up and copied some additional people on the thread.

> November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed.

> July 27, 2026: Published

Quite the generous timeline on this person's behalf.

Xeoncross - 2 hours ago

There is security that protects users and then there is security theater that provides litigation protection for the company.

Sometimes overlapping, but they are not the same thing.

spockz - 3 hours ago

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car.

Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy.

On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?

superloika - 2 hours ago

I feel obligated to post this very cool FSF Car right-to-repair video https://www.fsf.org/videos/fight-to-repair/

nhance - 3 hours ago

I love this sort of content on HN. I am very curious what the impact of powerful AI has on these type of things