Honda’s e-commerce platform has security flaws that may have been used to get uncontrolled access to private dealer data.
In a study released last week, security researcher Eaton Zveare said that “broken/missing access controls made it possible to access all data on the platform, even when logged in as a test account.”
The platform is made for firms selling lawn & garden, marine, and power equipment. The Japanese company’s vehicle division is unaffected.
In essence, the hack uses a password reset feature on one of Honda’s websites, Power Equipment Tech Express (PETE), to reset any account’s password and gain complete admin access read more Password Reset Hack Exposed in Honda E-Commerce Platform, Dealers Data at Risk.
Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cybersecurity awareness, and the latest cybersecurity news to safeguard your digital world.
