A researcher walked up the URL tree of the My Eicher fleet platform and found unauthenticated internal APIs listing 748,000 customers, 2.5 million one-time passwords going back to 2021, and 76,000 identity documents, enough to take over any account and track 676,000 commercial vehicles in real time.
Read the full story: One Open API Exposed 676,000 Eicher Trucks to Takeover →
Transcript
A researcher found this by doing almost nothing. He took the API address the Eicher trucking app already used, and deleted part of the path to reach the parent endpoint. It just answered, no login required. Behind it sat a directory of seven hundred forty eight thousand customers, a store of two point five million one time passcodes going back to 2021, and a password reset route that never checked who was asking. Either path gets you a real, valid session as any user. From there: live GPS tracking on six hundred seventy six thousand commercial trucks, plus seventy six thousand uploaded ID documents, Aadhaar cards, driving licenses. The researcher reported this in November 2025. The vendor patched the main bug seventeen days later and then went quiet for eight months. That gap, not the bug itself, is the real story here.