Laos Post

Monday, Aug 11, 2025

Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere

A security researcher discovered vulnerabilities in a carmaker’s online dealership portal, allowing potential remote access to vehicles and sensitive customer data.
A security researcher has uncovered significant flaws in a carmaker’s online dealership portal that exposed the private information of customers and could have enabled hackers to remotely access vehicles.

Eaton Zveare, a security researcher at Harness, discovered that the vulnerabilities allowed the creation of an admin account with full access to the carmaker’s centralized web portal.

This access could have allowed a hacker to view personal and financial data, track vehicles, and even pair cars with mobile accounts to control vehicle functions remotely.

The flaws were traced to an issue with the portal’s login system, where buggy code in the user’s browser allowed bypassing login security checks.

Once inside, the hacker could access data from over 1,000 dealerships across the United States.

Zveare found a national consumer lookup tool that allowed users to search vehicle and driver data by entering just a customer’s name or car’s unique identification number.

He also demonstrated how the vulnerability could have enabled unauthorized access to car functions such as unlocking vehicles.

Additionally, Zveare identified that the portal allowed users to impersonate others, bypassing the need for login credentials, and access dealer systems linked via single sign-on.

He found personally identifiable information, financial details, and real-time location tracking of rental or courtesy cars.

Zveare reported the issue to the carmaker, who fixed the vulnerabilities within a week.

The flaws highlight the risks of poor authentication in securing sensitive data and vehicle control systems.
Newsletter

Related Articles

Laos Post
0:00
0:00
Close
RFK Jr. Announces HHS Investigation into Big Pharma Incentives to Doctors
Australia to Recognize the State of Palestine at UN Assembly
The Collapse of the Programmer Dream: AI Experts Now the Real High-Earners
Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere
Street justice isn’t pretty but how else do you deal with this kind of insanity? Sometimes someone needs to standup and say something
Trump Urges Intel CEO Lip-Bu Tan to Resign Over Alleged Chinese Business Ties
US Justice Department Seeks Release of Epstein and Maxwell Grand Jury Exhibits Amid Legal and Victim Challenges
Surge in Foreign Investment in Asian Stocks Amid AI Growth and Trade Optimism
French Senate Report Alleges State Cover‑Up in Perrier ‘Natural Mineral Water’ Scandal
British Labour Government Utilizes Counter-Terrorism Tools for Social Media Monitoring Against Legitimate Critics
OpenAI Launches GPT‑5, Its Most Advanced AI Model Yet
Chikungunya Virus Outbreak in Southern China: Over 7,000 Hospitalized
Brazilian President Lula says he’ll contact the leaders of BRICS states to propose a unified response to U.S. tariffs
Nine people have been hospitalized and dozens of salmonella cases have been reported after an outbreak of infections linked to certain brands of pistachios and pistachio-containing products, according to the Public Health Agency of Canada
US Charges Two Chinese Nationals for Illegal Nvidia AI Chip Exports
Texas Residents Face Water Restrictions While AI Data Centers Consume Millions of Gallons
U.S. Tariff Policy Triggers Market Volatility Amid Growing Global Trade Tensions
Tariffs, AI, and the Shifting U.S. Macro Landscape: Navigating a New Economic Regime
Representative Greene Urges H-1B Visa Cuts Amid U.S.-India Trade Tensions
Torrential rains lashed Hong Kong, shutting schools, hospitals and law courts, marking the highest daily rainfall for August since 1884
India Rejects U.S. Tariff Threat, Defends Russian Oil Purchases
United States Establishes Strategic Bitcoin Reserve and Digital Asset Stockpile
Thousands of Private ChatGPT Conversations Accidentally Indexed by Google
China Tightens Mineral Controls, Curtailing Critical Inputs for Western Defence Contractors
U.S. Tariffs Surge to Highest Levels in Nearly a Century Under Second Trump Term
Ong Beng Seng Pleads Guilty in Corruption Case Linked to Former Singapore Transport Minister
BP’s Largest Oil and Gas Find in 25 Years Uncovered Offshore Brazil
Italy Fines Shein One Million Euros for Misleading Sustainability Claims
China Enforces Comprehensive Ban on Cryptocurrency Activities
Decline in Tourism in Majorca Amidst Ongoing Anti-Tourism Protests
British Tourist Dies Following Hair Transplant in Turkey, Police Investigate
Poland Begins Excavation at Dziemiany After New Clue to World War II‑Era Nazi Treasure
WhatsApp Users Targeted in New Scam Involving Account Takeovers
Trump Deploys Nuclear Submarines After Threats from Former Russian President Medvedev
Germany’s Economic Breakdown and the Return of Militarization: From Industrial Collapse to a New Offensive Strategy
JD Vance Warns Europe Faces “Civilizational Suicide” Over Open Borders and Speech Limits
Trump Administration Finalizes Broad Tariff Increases on Global Trade Partners
Thailand Secures Reduced U.S. Tariff Rate of Nineteen Percent After Trade Negotiations
Cambodia Accepts Thailand’s Proposal to Relocate Border Talks to Malaysia with Key International Observers
JD.com Launches €2.2 Billion Bid for German Electronics Retailer Ceconomy
Azerbaijan Proceeds with Plan to Legalise Casinos on Artificial Islands
House Republicans Move to Defund OECD Over Global Tax Dispute
Hong Kong Reports 12% Surge in Tourist Arrivals in First Half of 2025
Trump Steamrolls EU in Landmark Trade Win: US–EU Trade Deal Imposes 15% Tariff on European Imports
Thailand and Cambodia prepare for ceasefire talks as clashes intensify
The British propaganda channel BBC News lies again.
Deputy attorney general's second day of meeting with Ghislaine Maxwell has concluded
Intel Reports Revenue Beats but Sees 81% Rise in Losses
Chinese Firms Urged to Integrate into ASEAN Supply Chains as US Tightens Tariffs on Transshipments
CAMBODIA VS THAILAND: AIR POWER? WHAT AIR POWER?
×