Trendora
Feed
9Hacker News·security

Unauthenticated APIs in My Eicher expose fleet accounts and vehicles

AI summary

A security researcher found unauthenticated internal and admin APIs in Volvo/Eicher’s My Eicher fleet management platform. The flaw enabled access to customer data, OTPs, and account takeover, which could lead to control of entire commercial fleets and exposed sensitive documents at scale.

In-depth analysis

AI-generated, audience-specific — grounded in this story.

Technologies in this story

Discussion

No comments yet. Start the discussion.

Unauthenticated APIs in My Eicher expose fleet accounts and vehicles · Trendora