Kia dealer portal flaw could let attackers hack millions of cars

Teilen:

A group of security researchers discovered critical flaws in Kia’s dealer portal that could let hackers locate and steal millions of Kia cars made after 2013 using just the targeted vehicle’s license plate.

Almost two years ago, in 2022, some of the hackers in this group, including security researcher and bug bounty hunter Sam Curry, found other critical vulnerabilities impacting over a dozen car companies that would’ve allowed criminals to remotely locate, disable starters, unlock, and start over 15 million vehicles made by Ferrari, BMW, Rolls Royce, Porsche, and other carmakers.

Today, Curry revealed that the Kia web portal vulnerabilities discovered on June 11th, 2024, could be exploited to control any Kia vehicle equipped with remote hardware in under 30 seconds, “regardless of whether it had an active Kia Connect subscription.”

The flaws also exposed car owners’ sensitive personal information, including their name, phone number, email address, and physical address, and could have enabled attackers to add themselves as a second user on the targeted vehicles without the owners’ knowledge.

To further demonstrate the issue, the team built a tool showing how an attacker could enter a vehicle’s license plate and, within 30 seconds, remotely lock or unlock the car, start or stop it, honk the horn, or locate the vehicle.

The researchers registered a dealer account on Kia’s kiaconnect.kdealer.com dealer portal to gain access to this information.

Once authenticated, they generated a valid access token that gave them access to backend dealer APIs, giving them critical details about the vehicle owner and full access to the car’s remote controls.

They found that attackers could use the backend dealer API to:

  • Generate a dealer token and retrieve it from the HTTP response
  • Access the victim’s email address and phone number
  • Modify the owner’s access permissions using leaked information
  • Add an attacker-controlled email to the victim’s vehicle, allowing for remote commands

“The HTTP response contained the vehicle owner’s name, phone number, and email address. We were able to authenticate into the dealer portal using our normal app credentials and the modified channel header,” Curry said.

From there, attackers could enter a vehicle’s VIN (vehicle identification number) through the API and remotely track, unlock, start, or honk the car without the owner’s knowledge.

The Kia web portal flaws allowed silent, unauthorized access to a vehicle since, as Curry explained, “from the victim’s side, there was no notification that their vehicle had been accessed nor their access permissions modified.”

“These vulnerabilities have since been fixed, this tool was never released, and the Kia team has validated this was never exploited maliciously,” Curry added.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:38 am, Jan. 26, 2025
Wetter-Symbol 3°C
L: 1° | H: 4°
wenige Wolken
Luftfeuchtigkeit: 81 %
Druck: 1006 mb
Wind: 5 mph SW
Windböe: 8 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 21%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:47 am
Sonnenuntergang: 4:38 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
1° | 4°°C 1 mm 100% 19 mph 93 % 1005 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 22 mph 90 % 984 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
7° | 9°°C 1 mm 100% 21 mph 86 % 996 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
5° | 7°°C 1 mm 100% 15 mph 93 % 1001 mb 0 mm/h
Do. Jan. 30 9:00 pm
Wetter-Symbol
3° | 6°°C 0.93 mm 93% 10 mph 95 % 1023 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 9 mph 81 % 1005 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
3° | 5°°C 0 mm 0% 14 mph 79 % 1004 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 17 mph 81 % 1000 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
5° | 5°°C 1 mm 100% 19 mph 93 % 990 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 1 mm 100% 14 mph 84 % 988 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 16 mph 79 % 986 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 20 mph 90 % 979 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
7° | 7°°C 1 mm 100% 14 mph 77 % 982 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,353.22
0.48%
Ethereum(ETH)
€3,195.88
1.51%
XRP(XRP)
€2.99
0.78%
Fesseln(USDT)
€0.95
-0.01%
Solana(SOL)
€246.98
3.28%
Dogecoin(DOGE)
€0.339619
1.47%
USDC(USDC)
€0.95
-0.01%
Shiba Inu(SHIB)
€0.000019
0.87%
Pepe(PEPE)
€0.000014
1.38%
Peanut das Eichhörnchen(PNUT)
€0.341643
3.03%
Nach oben scrollen