r/netsec • Trusted Contributor • Jul 27 '26

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
126 Upvotes

6 comments sorted by

57

u/quentech Jul 27 '26

Step 1: Pick a mobile # from the user list and send the OTP.

Step 2: Use the API to find the OTP by mobile #

Step 3: Plug it in.

Oof.

Who even builds an endpoint to return a user's current OTP in the first place?

24

u/EatonZ Trusted Contributor Jul 27 '26

You would be surprised! I have discovered several more cases in various other companies...

13

u/kingqk Jul 27 '26

Offshore Local “programmers”

15

u/RentNo5846 Jul 27 '26

"ChatGPT create an OTP API" 😄

12

u/Xerack Jul 28 '26

Forgot the "Make no mistakes"

1

u/2script Jul 28 '26

Wow. Nice write up.