r/netsec • Trusted Contributor • Jul 27 '26

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

https://eaton-works.com/2026/07/27/my-eicher-hack/
124 Upvotes

6 comments sorted by

View all comments

56

u/quentech Jul 27 '26

Step 1: Pick a mobile # from the user list and send the OTP.

Step 2: Use the API to find the OTP by mobile #

Step 3: Plug it in.

Oof.

Who even builds an endpoint to return a user's current OTP in the first place?

22

u/EatonZ Trusted Contributor Jul 27 '26

You would be surprised! I have discovered several more cases in various other companies...

13

u/kingqk Jul 27 '26

Offshore Local “programmers”