Monaco Times

Sustainability, Heritage, Exclusivity.
Wednesday, Aug 13, 2025

Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere

A security researcher discovered vulnerabilities in a carmaker’s online dealership portal, allowing potential remote access to vehicles and sensitive customer data.
A security researcher has uncovered significant flaws in a carmaker’s online dealership portal that exposed the private information of customers and could have enabled hackers to remotely access vehicles.

Eaton Zveare, a security researcher at Harness, discovered that the vulnerabilities allowed the creation of an admin account with full access to the carmaker’s centralized web portal.

This access could have allowed a hacker to view personal and financial data, track vehicles, and even pair cars with mobile accounts to control vehicle functions remotely.

The flaws were traced to an issue with the portal’s login system, where buggy code in the user’s browser allowed bypassing login security checks.

Once inside, the hacker could access data from over 1,000 dealerships across the United States.

Zveare found a national consumer lookup tool that allowed users to search vehicle and driver data by entering just a customer’s name or car’s unique identification number.

He also demonstrated how the vulnerability could have enabled unauthorized access to car functions such as unlocking vehicles.

Additionally, Zveare identified that the portal allowed users to impersonate others, bypassing the need for login credentials, and access dealer systems linked via single sign-on.

He found personally identifiable information, financial details, and real-time location tracking of rental or courtesy cars.

Zveare reported the issue to the carmaker, who fixed the vulnerabilities within a week.

The flaws highlight the risks of poor authentication in securing sensitive data and vehicle control systems.
Newsletter

Related Articles

0:00
0:00
Close
Denmark Revives EU ‘Chat Control’ Proposal for Encrypted Message Scanning
Perplexity makes unsolicited $34.5 billion all-cash offer for Google’s Chrome browser
Cristiano Ronaldo and Georgina Rodríguez announce engagement
Private Welsh island with 19th-century fort listed for sale at over £3 million
The Collapse of the Programmer Dream: AI Experts Now the Real High-Earners
Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere
Denmark Pushes for Child Sexual Abuse Scanning Bill in EU, Could Be Adopted by October 2025
French Senate Report Alleges State Cover‑Up in Perrier ‘Natural Mineral Water’ Scandal
OpenAI Launches GPT‑5, Its Most Advanced AI Model Yet
U.S. Tariff Policy Triggers Market Volatility Amid Growing Global Trade Tensions
Tariffs, AI, and the Shifting U.S. Macro Landscape: Navigating a New Economic Regime
OpenAI’s Bold Bet: Teaching AI to Think, Not Just Chat
Switzerland Celebrates 734 Years of Independence Amid Global Changes
Poland Begins Excavation at Dziemiany After New Clue to World War II‑Era Nazi Treasure
House Republicans Move to Defund OECD Over Global Tax Dispute
France Opens Criminal Investigation into X Over Algorithm Manipulation Allegations
Politics is a good business: Barack Obama’s Reported Net Worth Growth, 1990–2025
UN's Top Court Declares Environmental Protection a Legal Obligation Under International Law
Pogacar Extends Dominance with Stage Fifteen Triumph at Tour de France
Centrist Criticism of von der Leyen Resurfaces as she Survives EU Confidence Vote
FIFA Pressured to Rethink World Cup Calendar Due to Climate Change
Church of England Removes 1991 Sexuality Guidelines from Clergy Selection
Jeff Bezos Considers Purchasing Condé Nast as a Wedding Gift
Bal des Pompiers: A Celebration of Community and Firefighter Culture in France
Jamie Dimon Warns Europe Is Losing Global Competitiveness and Flags Market Complacency
Polish MEP: “Dear Leftists - China is laughing at you, Russia is laughing, India is laughing”
Christian Horner Departs Red Bull Amid Internal Turmoil
AI Raises Alarms Over Long-Term Job Security
Air France-KLM Acquires Majority Stake in Scandinavian Airlines
King Charles Plans Significant Role for Prince Harry in Coronation
Marc Marquez Claims Victory at Dutch Grand Prix Amidst Family Misfortune
Jeff Bezos and Lauren Sánchez Host Lavish Wedding in Venice Amid Protests
NATO Members Agree to 5% Defense Spending Target by 2035
MonacoTech Selects Six Startups for Expert Review
The Evolving Landscape of the Art Market: Insights from Experts
Diverse Workforce in Monaco: 145 Nationalities Represented Among Private Sector Employees
AS Monaco Loans Left Back Valy Konaté to Cercle Bruges for 2025-2026 Season
French Nurses Participate in National Congress on Psychogeriatrics
Oman Set to Introduce Personal Income Tax, First in Gulf
US strikes Iran nuclear sites, Trump says
Political Turmoil Resurfaces in Belgium Amid Economic Concerns
EU Proposes Ban on New Russian Gas Contracts
Trump Reports $57 Million Earnings from Crypto Venture
64th Monte-Carlo Television Festival Opens with Global Talent and Premieres
HSBC Accelerates Chairman Succession as Mark Tucker Prepares Departure
UK and EU Reach Agreement on Gibraltar's Schengen Integration
Israeli Finance Minister Imposes Banking Penalties on Palestinians
U.S. Inflation Rises to 2.4% in May Amid Trade Tensions
Trump's Policies Prompt Decline in Chinese Student Enrollment in U.S.
Global Oceans Near Record Temperatures as CO₂ Levels Climb
×