Skip to content
Tech News
← Back to articles

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

read original more articles
Why This Matters

The discovery of a critical vulnerability in Volvo/Eicher's My Eicher fleet management platform highlights significant security risks for commercial vehicle operators and the broader automotive industry. Exploiting such flaws could allow malicious actors to take control of entire vehicle fleets, posing safety, privacy, and operational concerns for thousands of users and businesses. This underscores the urgent need for robust cybersecurity measures in connected vehicle systems to protect critical infrastructure and user data.

Key Takeaways

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

Eaton • Jul 27, 2026

Copy Link Share

Key Points / Summary

VE Commercial Vehicles, a joint venture between the Volvo Group and Eicher Motors, builds and maintains a fleet management system called My Eicher for Indian commercial vehicle customers. “My Eicher is a complete fleet management & vehicle GPS tracking system designed for commercial vehicle owners, fleet managers, & operators. With our highly advanced telematics platform, you can take control of your fleet like never before.”

A vulnerability was found in the APIs that made it possible to discover hidden, unauthenticated internal/admin APIs. These APIs could be used to gain high-level access to systems and even enable account takeover.

Account takeover made it possible to gain control over a person’s (or company’s) entire fleet, which could consist of hundreds of vehicles.

Exposed data by the numbers. As of November 2024, it was announced that 275k vehicles and 115k customers are registered. It is unclear why some of these numbers pulled from the API are significantly higher. 748k customers 174k users 186k persons 676k vehicles 76k documents (Aadhaar cards, driving licenses, etc)

Welcome to my next blockbuster automotive hack! This one has been in the works for a long time with roots going back to early 2024 when I disclosed the Toyota insurance company hack. Fun fact: I was actually trying to find a vulnerability in My Eicher at that time, but was unsuccessful. It wasn’t until more than a year later in 2025 that I stumbled upon a breakthrough that cracked My Eicher wide open.

... continue reading