The Smart Bus Tech Stack
ADAS gives drivers real-time safety feedback using cameras, sensors, and radar. It monitors the road and the driver, flagging pedestrians, lane drift, drowsiness, and phone use. APS links the bus to the central control station, passenger apps, and roadside signs. An M2M router sits at the center, handling GPS tracking, remote control, and OTA updates over 4G and 5G. Every connection is a potential entry point.
Free WiFi to Full Router Access
After connecting to the bus WiFi, Yu found the M2M router’s IP and opened a login page. The default password failed. The router ran BOA, a notoriously insecure web server with a public auth-bypass CVE. That CVE worked. Inside the settings page, a password field was marked hidden in HTML. Opening developer tools revealed the plaintext credential. From there, SSH connected without friction. A port scan showed dozens of open services. A command injection bug gave shell access. MQTT credentials appeared in a system command output.
DVR Access and ADAS Web Server Exposure
The router’s DHCP table showed a device on a different subnet. It was a DVR, part of the ADAS system, recording footage from bus cameras. The login credentials: admin/admin. Live video of the driver was accessible immediately. Inside the DVR menu, a ping utility had a command injection flaw. The ADAS web interface ran on port 80 with no TLS. Directory scanning found /m (live speed and location for every bus in the fleet), /console (an admin panel), and /media (stored video recordings anyone could browse without logging in).
Unauthenticated APIs Serving Live Fleet Data
Packet capture pointed to another IP. Visiting it returned a full API help page with no authentication. The route API, master API, and ticket list endpoints all worked without tokens. The data matched the real bus: speed, GPS coordinates, and the driver’s name in Chinese characters. The driver’s name matched what was displayed on the LED sign inside the bus. The same API exposed the open-trip-planner route system. No session token, no API key, no login. Everything was live, production data.
Forging APS Packets: No Auth, No Encryption
Traffic analysis found UDP packets from the APS system. Taiwan’s industrial standard for bus communication defines the packet format. A Python decode script, written with ChatGPT, parsed GPS coordinates and average speed from live packets. The same format accepts forged packets. A man-in-the-middle attacker could place the bus in the Pacific Ocean or trigger a fake emergency signal. No encryption, no authentication in the APS standard. The device had passed official certification from Taiwan’s Association of Information and Communication Standard. That certification covered paper, not practice.
Notable Quotes
By accident, I hacked the bus. Chiao-Lin Yu · ▶ 3:11
a professional F12 hacker. Chiao-Lin Yu · ▶ 8:48
This is not just a problem for one bus. Chiao-Lin Yu · ▶ 20:02
productive bus ride I ever had. Yeah. Chiao-Lin Yu · ▶ 19:28
Key Takeaways
- Default admin/admin credentials on safety-critical bus DVR hardware enabled live video access from passenger WiFi.
- A public BOA auth-bypass CVE remained unpatched on a device that held an official Taiwanese security certification.
- The APS UDP protocol carries no encryption or authentication, letting any observer forge GPS positions or fake emergency alerts fleet-wide.
About the Speaker(s)
Chiao-Lin Yu, known as Steven Meow, is a Senior Red Team Cyber Threat Researcher at Trend Micro Taiwan. He holds over a dozen offensive security certifications including OSCE³, OSEP, OSWE, and OSCP, and has disclosed more than 30 CVE vulnerabilities in products from VMware, D-Link, and Zyxel. He has presented at HITCON Training 2025, Security BSides Tokyo 2023, and CYBERSEC 2024 and 2025.
Kai-Ching Wang, known as Keniver, is a Senior Security Researcher at CHT Security. His work focuses on red team assessments and IoT device security, with recent research targeting cloud-native infrastructure. He has presented at SECCON in Japan and HITCON in Taiwan.