• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»Safety flaws in a preferred GPS tracker are exposing one million car places – DailyTech
Tech News

Safety flaws in a preferred GPS tracker are exposing one million car places – DailyTech

July 19, 2022Updated:July 19, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Security flaws in a popular GPS tracker are exposing a million vehicle locations – TechCrunch
Share
Facebook Twitter LinkedIn Pinterest Email

Safety vulnerabilities in a preferred Chinese language-built GPS car tracker will be simply exploited to trace and remotely minimize the engines of at the least one million automobiles world wide, in accordance with new analysis. Worse, the corporate that makes the GPS trackers has made no effort to repair them.

Cybersecurity startup BitSight stated it discovered six vulnerabilities within the MV720, a hardwired GPS tracker constructed by Micodus, a Shenzhen,-based electronics maker, which claims greater than 1.5 million GPS trackers in use in the present day throughout greater than 420,000 clients worldwide, together with firms with fleets of automobiles, legislation enforcement businesses, militaries and nationwide governments. BitSight stated it additionally discovered the GPS trackers utilized by Fortune 50 firms and a nuclear energy plant operator.

However the safety flaws will be simply and remotely exploited to trace any car in real-time, entry previous routes, and minimize the engines of automobiles in movement.

Pedro Umbelino, principal safety researcher at BitSight who authored the report seen by DailyTech earlier than its publication, stated the vulnerabilities are “not tough to use,” and that the character of the issues leaves “vital questions concerning the vulnerability of different fashions,” suggesting the bugs might not be restricted to the one Micodus GPS tracker mannequin.

Given the severity of the bugs and that there aren’t any fixes, each BitSight and CISA, the U.S. authorities’s cybersecurity advisory company, warned car homeowners to take away the units as quickly as potential to mitigate the danger.

The six vulnerabilities range in severity and exploitability, however all however one rank as “excessive” severity or higher. Among the bugs are within the GPS tracker itself, whereas others are within the net dashboard that clients use to trace their car fleets.

See also  Does economic and geopolitical instability affect your startup’s TAM? • DailyTech

Essentially the most extreme flaw is a hardcoded password that can be utilized to realize full management of any GPS tracker, entry to automobiles’ real-time location and previous routes, and remotely minimize off gas to automobiles. As a result of the password is embedded immediately into the code of the Android app, anybody can dig across the code and discover it.

A map with purple factors representing a MiCODUS consumer. Picture Credit: BitSight/equipped.

The analysis additionally discovered that the GPS tracker comes with a default password of “123456,” permitting anybody entry to GPS trackers that haven’t modified their machine’s password. BitSight discovered 95% of a pattern of 1,000 units it examined had been accessible with an unchanged default password, possible as a result of machine homeowners aren’t prompted to vary the machine’s password on setup.

Two of the remaining vulnerabilities, often called insecure direct object references — or IDORs — permit a logged-in consumer to entry information from a susceptible GPS tracker that didn’t belong to them, and generate spreadsheets containing machine exercise, corresponding to previous places and routes.

The researchers stated they discovered susceptible Micodus GPS trackers all around the world, with the very best focus of units in Ukraine, Russia, Uzbekistan, and Brazil, in addition to throughout Europe, together with Spain, Poland, Germany and France. Kevin Lengthy, a spokesperson for BitSight, advised DailyTech that it noticed a smaller proportion of units in the USA however that the determine is probably going “hundreds” of units.

BitSight CEO Stephen Harvey stated the vulnerabilities have the potential to end in “disastrous penalties” for affected car homeowners. The safety firm first contacted Micodus in September 2021, however no efforts had been made to repair the vulnerabilities forward of the report’s publication. Safety researchers sometimes give firms three months to repair vulnerabilities earlier than they’re made public, giving the builders time to remediate earlier than particulars of the vulnerabilities are printed.

See also  Hyundai Motor eyes acquisition of Korean lidar-free self-driving startup 42dot – DailyTech

Micodus didn’t reply to DailyTech’s request for remark despatched previous to publication.

Source link

DailyTech exposing flaws GPS locations million Popular security tracker vehicle
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitdefender Total Security review

March 6, 2024

Avast Premium Security review

March 6, 2024

Eset Home Security Ultimate review

January 23, 2024

AVG Internet Security review

October 31, 2023
Add A Comment

Comments are closed.

Editors Picks

Smeg EGF03 Espresso Coffee Machine with Grinder review

October 17, 2023

Tribit FlyBuds C1 review

July 6, 2023

DoD announces launch of a new bug bounty program

July 4, 2022

Garmin Vivomove Trend review

April 18, 2023

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.