Exploiting Volvo/Eicher's Fleet Platform to Gain Control Over All Users/Vehicles
Exploiting Volvo/Eicher's Fleet Platform to Gain Control Over All Users/Vehicles
Overview
The vulnerability disclosed by EatonZ enabled control over every user and vehicle linked to Volvo/Eicher's fleet platform.
Timeline of Disclosure and Fix
According to a comment by @darknavi on the Hacker News thread:
November 3, 2025: Reported. November 10, 2025: No response, followed up. November 17, 2025: No response, followed up and copied some additional people on the thread. November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. July 27, 2026: Published Quite the generous timeline on this person's behalf.
This shows that the issue was privately reported in early November 2025, remediated by November 20, 2025, and publicly disclosed eight months later.
Technical Implications
The post title states that the exploit allowed "gain[ing] control over all users/vehicles" via Volvo/Eicher's fleet platform. While the original article details are not available in the provided source, the timeline comment confirms that internal APIs were blocked after the fix, indicating the vulnerability resided in those APIs.
Community Reaction
- @nhance expressed interest in how powerful AI might affect similar security issues.
- @spockz highlighted concerns about reliance on cloud management for vehicle operation, citing a BMW that would not start without phone reception and questioning why such dependency is allowed.
- @Xeoncross distinguished between security that protects users and security theater that mainly provides litigation protection for companies.
- @superloika shared a link to an FSF video on the right‑to‑repair movement for cars.
- @wkjagt wondered whether the findings affect older models such as a 1981 Volvo 244.
- @tesnorindian noted that a few weeks prior, several BMS apps based on Bluetooth were banned in India after being misused to remotely disable e‑rickshaws, stressing that securing battery management systems should be a top priority for EVs.
Broader Implications
The incident underscores several recurring themes in automotive cybersecurity:
- Cloud dependency: Modern vehicles often require constant connectivity to manufacturer clouds for basic functions, creating a single point of failure.
- Disclosure timelines: The lengthy gap between private remediation and public release raises questions about the balance between giving vendors time to fix issues and informing users about past risks.
- AI and automation: As noted by commenters, advances in AI could both aid attackers in finding vulnerabilities and help defenders in securing complex fleets.
- Right‑to‑repair and user control: Discussions point to a desire for more direct device‑to‑vehicle key exchange, reducing reliance on opaque cloud services.
- Regulatory response: The banning of insecure BMS apps in India illustrates how regulators may act when vehicle‑related vulnerabilities are exploited in the wild.
These takeaways are drawn solely from the Hacker News post and its accompanying comments; no additional facts have been invented.