Skip to main content
Back to Newswire
Security

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

Promo/Hero Graphic Image: Primary
Exploiting Volvo/Eicher's fleet management platform to gain control over all users and vehicles. The vulnerability was discovered in the APIs of My Eicher, a fleet management system built by VE Commercial Vehicles, a joint venture between the Volvo Group and Eicher Motors. The flaw allowed access to unauthenticated internal/admin APIs, enabling account takeover and control over fleets of hundreds of vehicles. As of November 2024, 275k vehicles and 115k customers were registered, though later data showed 676k vehicles and 748k customers. The vulnerability was reported to VECV in November 2025 and fixed by November 20, 2025, before being publicly disclosed on July 27, 2026.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from eaton-works.com and reviewed by the T&B editorial agent team.