7 ms·
Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
- darknavi 2mo ago> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.
- greyface- 2mo agoAnd terrible (non-)response from VECV, if they have any interest in receiving timely disclosure from future researchers.
- deleted 2mo ago[deleted]
- r_lee 2mo agoreminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
- cromka 2mo agoreminder, Volvo is Chinese.
- loloquwowndueo 2mo agoHow so? Sources?
- solarkraft 2mo agoGeely bought it from Ford in 2010. https://www.reuters.com/article/business/geely-signs-18-billion-deal-for-volvo-idUSTRE62Q1EH/ https://www.reuters.com/article/business/geely-signs-18-bill...
- dhathorn 2mo agoThat would be Volvo cars. tfa is about Volvo group, which is Swedish and makes among other things Volvo trucks. (Or HGVs as they might be called in Europe)
- cromka 2mo agoOh, fair. I assumed this was consumer cars.
- solarkraft 2mo agoOh, great point!
- johanmrtnsn 2mo agoAre you thinking about Volvo cars? There are two Volvo companies, Volvo cars and Volvo group. This seems to be about Volvo group which makes commercial vehicles like trucks and busses.
- ashu1461 2mo agoAlso the exploit is not directly via volvo but with a third party
- mpdpsycho 2mo agoI don’t know why particularly here over elsewhere, but this thought really makes me feel disappointment in the whole chain of humans responsible for the cost optimization away of product integrity. Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.
- r_lee 2mo agothere's no point in being moral when these companies with their immense resources will just ignore you or refuse to give a measly bounty things won't change until they have to make an effort
- voakbasda 2mo agoThis. If they don’t feel pressure to pay, they won’t. More people should make them pay.
- nhance 2mo agoI love this sort of content on HN. I am very curious what the impact of powerful AI has on these type of things
- EatonZ 2mo agoIn this case, AI wasn't used for anything.
- dotancohen 2mo agoI believe that it was used to generate the post that you replied to.
- formerly_proven 2mo agoThe person you are replying to wrote that post.
- kjs3 2mo agoAI driven/automated farming for kharma will only get worse...
- spockz 2mo agoThis is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?
- motbus3 2mo agoHow they will be able to block you from using your car when they deem that you should by a new one? Or how would they be able to make something a paid feature after you bought it? You need to support these poor fellas
- voakbasda 2mo agoI expect a firmware update to “accidentally” brick parts of my new car at some point, then claim it takes them 6 months to roll back the mistake. That is how they will do it.
- samdhar7 2mo ago[flagged]
- gruez 2mo ago>On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed? Surely there's more to this story? AFAIK last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time.
- xp84 2mo ago
- Xeoncross 2mo agoThere is security that protects users and then there is security theater that provides litigation protection for the company. Sometimes overlapping, but they are not the same thing.
- pixel_popping 2mo agoBoth are important actually, the security theater often deter from trying because it could be too annoying, it's generally "free to do", along with additional obfuscation, it's useful too but does not replace proper security, but from experience, theater+obfuscation+security is greater security than just security.
- superloika 2mo agoI feel obligated to post this very cool FSF Car right-to-repair video https://www.fsf.org/videos/fight-to-repair/ https://www.fsf.org/videos/fight-to-repair/
- wkjagt 2mo agoI should look into how this affects my 1981 Volvo 244
- tesnorindian 2mo agoNo wonder a few weeks before few BMS apps based on BT was banned in India as they were misused for remote disabling of e-Rickshaws. https://timesofindia.indiatimes.com/business/india-business/centre-removes-bat-bms-linked-apps-from-app-stores-after-e-rickshaw-remote-shutdown-reports/articleshow/132155150.cms https://timesofindia.indiatimes.com/business/india-business/... Securing BMS should be the top priority for EVs. Keeping unsecured BT connection in BMS would be the worst thing.
- MisterTea 2mo agoI was recently researching building large LiFePo4 battery banks and realized just about every BMS I looked at featured a BT connection. That was disappointing as I assume there is little to no security for pairing ans communication. Anyone could sabotage or shut down a battery bank.