9Hacker News·security
Unauthenticated APIs in My Eicher expose fleet accounts and vehicles

AI summary
A security researcher found unauthenticated internal and admin APIs in Volvo/Eicher’s My Eicher fleet management platform. The flaw enabled access to customer data, OTPs, and account takeover, which could lead to control of entire commercial fleets and exposed sensitive documents at scale.
In-depth analysis
AI-generated, audience-specific — grounded in this story.
Technologies in this story
Discussion
No comments yet. Start the discussion.