Skip to content
Henri Emategui·

🚨Electric Scooter Company's Panel Left Wide Open

Scooter company's admin panel left wide open for anyone to find and exploit

TL;DR

A security researcher discovered that the admin panel of an electric scooter service was accessible without authentication. The flaw allowed access to fleet data and control over scooters, highlighting critical vulnerabilities in IoT deployments.

Security researchers found a major vulnerability in an electric scooter company's admin panel: it could be accessed without any authentication. This oversight exposed sensitive information about the fleet, including vehicle locations and user details. Researchers were able to unlock real scooters remotely using the compromised system. The incident underscores critical security gaps in IoT deployments, especially for services that rely heavily on mobile apps and backend APIs.

Electric Scooter Company's Panel Left Wide Open — Henri Emategui

Key Points

1

Researchers found the Angular-based operator panel at painel.electricscootercompany.com.br without authentication (8/24).

2

The public WordPress REST API revealed user ID 1 as 'admin' with slug 'electricscootercompany', exposing sensitive data (16/24).

3

A brute force attack on the panel login successfully obtained a password, granting admin-level access for over two years (17-19/24).

4

With valid session tokens, researchers could read fleet maps and control IoT devices, unlocking real scooters remotely (20-26/24).

5

The incident highlights critical security gaps in IoT deployments, especially those relying on mobile apps and backend APIs for user management (17-26/24)

Why It Matters

If you're deploying any IoT devices or managing fleets with mobile apps, this is a wake-up call. The scooter company's admin panel was left wide open, allowing anyone to access sensitive data and control over physical vehicles. This highlights the critical need for robust authentication mechanisms and regular security audits in IoT deployments.

iotadmin-panel-leakfleet-managementsecurity-breach

Frequently Asked Questions

Why does this matter?

If you're deploying any IoT devices or managing fleets with mobile apps, this is a wake-up call. The scooter company's admin panel was left wide open, allowing anyone to access sensitive data and control over physical vehicles. This highlights the critical need for robust authentication mechanisms and regular security audits in IoT deployments.

What happened?

A security researcher discovered that the admin panel of an electric scooter service was accessible without authentication. The flaw allowed access to fleet data and control over scooters, highlighting critical vulnerabilities in IoT deployments.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,303 builders reading daily.

Also get