Registration Bypass Unlocks Admin Panel

▶ Watch (3:49)

A hidden registration form in the Angular front-end accepted a blank invite token. The server did not validate the token, creating a limited account. After profile update, a temporary session downloaded JavaScript bundles exposing admin endpoints. Patching two front-end checks — commenting out the “invalid dealer” message and replacing the access-denied redirect with an empty string — loaded the internal admin page due to a server-side authorization gap. The create user button appeared with checkboxes for national, regional, sales, and finance rights. Checking all produced a national admin account.

Admin Account Enables Car Takeover

▶ Watch (8:14)

The new admin account logged in and selected from 1,700 dealers. A customer lookup by VIN returned name, address, and phone number. The enrollment system reassigned a vehicle to the attacker’s consumer account with no verification beyond a pinky-swear prompt. The mobile app then allowed engine start, climate control, and real-time location tracking. Vehicles from model year 2012 onward were affected. If the owner never enrolled in the app, no email was sent — a silent takeover.

Internal Systems Expose PII and Financial Data

▶ Watch (12:52)

User impersonation bypassed two-factor authentication. Full access to the CSD loaner platform revealed driver’s license numbers, insurance policies, and dates of birth. The finance portal contained contract PDFs loaded with PII. Survey databases held 200,000 sales and 450,000 service entries. A demographic map covered over 9 million people. Inventory control allowed ordering or canceling car deliveries. The dealer email platform could send phishing emails from the dealer’s bank account.

Disclosure and the Simple Root Cause

▶ Watch (19:41)

The vulnerability was discovered January 26, 2025. The automaker fixed it within days through their VDP. Root cause: a single missing invite token verification on the registration endpoint. That one-line omission unlocked full admin access over 1,000 dealers. The researcher noted the same control could be achieved by keylogging a dealer employee. The affected vehicle population spans model year 2012 to present.

Notable Quotes

It’s just a silent takeover. Eaton Zveare · ▶ 12:52

they want you to pinky promise this because when you click continue, it doesn’t actually ask you for anything else. Eaton Zveare · ▶ 11:02

it was only the missing invite token verification that open this up Eaton Zveare · ▶ 20:52

Key Takeaways

  • Missing invite token validation granted national admin access to over 1,000 dealerships.
  • Remote car takeover (engine start, tracking) possible for any 2012+ vehicle.
  • Simple front-end patches bypassed authorization; automaker fixed in days.

About the Speaker(s)

Eaton Zveare is a senior security research engineer at Traceable by Harness. As a member of the ASPEN Labs team, he has contributed to the security of some of the world’s largest organizations by finding and responsibly disclosing many critical vulnerabilities. He is best known for his high-profile security disclosures in the automotive space.