Security Flaws in Auto Manufacturer’s Online Portal Allow Hackers to Unlock Vehicles Worldwide
A security specialist has disclosed that flaws in a major car manufacturer’s online dealership platform have put sensitive customer data and vehicle details at risk, potentially enabling hackers to remotely access consumer vehicles.
Eaton Zveare, a security researcher with the software delivery firm Harness, informed TechCrunch that the vulnerability he identified permitted the creation of an admin account, offering “unrestricted access” to the unnamed automaker’s central web platform.
This level of access could allow an attacker to view personal and financial data of the automaker’s customers, track vehicle locations, and enroll clients in features that would enable remote control over various car functions by either owners or malicious actors.
Zveare chose not to disclose the name of the company, emphasizing it was a prominent automaker with well-known sub-brands.
In an interview with TechCrunch prior to his presentation at the Def Con security conference in Las Vegas, Zveare elaborated on how these vulnerabilities underscore the security risks associated with dealership systems that provide extensive access to customer and vehicle data for employees and partners.
Zveare, who has previously identified weaknesses in automotive customer and vehicle management systems, stumbled upon this flaw earlier this year during a weekend project, as he explained to TechCrunch.
He remarked that while identifying the security issues within the portal’s login system was difficult, he eventually negated the login entirely by creating a new “national admin” account.
The flaws were critical because the erroneous code executed in the user’s browser upon accessing the portal’s login page, enabling the user—Zveare in this scenario—to modify the code and bypass the login security measures. Zveare informed TechCrunch that the automaker found no evidence of previous exploits, suggesting he was the first to discover and report the vulnerability.
Once logged in, the account allowed access to over 1,000 of the automaker’s dealerships nationwide, as Zveare pointed out.
“No one even realizes you’re quietly accessing all of these dealers’ data, which includes their financials, sensitive information, and leads,” Zveare explained, shedding light on the extent of his access.
Zveare uncovered a national consumer lookup tool within the dealership portal that permitted logged-in users to check vehicle and driver information for the specific automaker.
In one instance, Zveare used a vehicle’s unique identification number from a car parked in a public space to retrieve the owner’s information. He noted that this tool could let anyone look up an individual using just a customer’s first and last name.
With access to the portal, Zveare also indicated the ability to link any vehicle to a mobile account, enabling users to manage certain car functions remotely via an app, such as unlocking their vehicles.
Zveare tested this with a friend’s account, with their consent. He mentioned that transferring ownership to an account he controlled required merely a simple confirmation—essentially a “pinky promise”—that the user performing the transfer was legitimate.
“For my purposes, I simply consulted a friend who agreed to let me take over their car, and proceeded from there,” Zveare recounted. “But [the portal] could technically do this to anyone with just their name—which is quite unsettling—or I could easily target vehicles in parking lots.”
While Zveare didn’t investigate whether he could drive the car away, he suggested that this vulnerability could be exploited by thieves to break into vehicles and steal possessions, among other things.
Another major concern with accessing this automaker’s portal was that it provided entry to other dealers’ systems connected through single sign-on. Zveare explained that the automaker’s dealer systems were interconnected, allowing seamless navigation from one system to another.
Moreover, the portal incorporated a feature that allowed admins, like the account Zveare created, to “impersonate” other users, thereby gaining access to additional dealer systems as if they were that user without needing their login credentials. Zveare noted that this feature was reminiscent of something identified in a Toyota dealer portal in 2023.
“These are just security disasters waiting to occur,” Zveare commented about the impersonation feature.
Once accessing the portal, Zveare encountered personally identifiable customer information, some financial details, and telematics systems that enabled the real-time tracking of rental or courtesy cars, along with vehicles in transit across the nation, providing the option to cancel them—although Zveare opted not to test that functionality.
Zveare reported that the vulnerabilities were patched within a week in February 2025, shortly after he notified the automaker.
“The key takeaway is that just two simple API vulnerabilities opened the floodgates, and it always circles back to authentication,” Zveare concluded. “If you mismanage that, everything collapses.”


