Critical Security Flaws in Carmaker's Web Portal
Learn about the recent security vulnerabilities discovered in a carmaker's web portal and the potential consequences for customers.
Eaton Zveare is a prominent cybersecurity researcher and ethical hacker known for exposing vulnerabilities in automotive and gaming systems.[2][3][4] In his early career around 2013, he was part of a group led by programmer Anthony Clark that exploited a hack in EA Sports' FIFA game servers to generate and sell vast amounts of in-game currency, reportedly earning up to $500,000 daily at its peak.[1] Zveare purchased luxury items like a Mercedes AMG CLA 45 with cash proceeds, but the operation drew FBI scrutiny, leading to raids and asset seizures.[1] He and two collaborators pleaded guilty to charges, forfeiting profits to avoid prison, while Clark fought the case and was later convicted of conspiracy to commit wire fraud.[1][6] Transitioning to ethical hacking, Zveare has gained recognition as a white-hat researcher publishing findings via Eaton Works.[3] In June 2023, he disclosed flaws in Honda's e-commerce platform (Honda Dealer Sites) and Power Equipment Tech Express (PETE) websites, including a weak password reset API that exposed over 1,090 dealer emails, 3,588 dealer accounts, 11,034 customer emails, and 21,393 orders using just a registered email from a public YouTube video.[3] The sites were deactivated post-disclosure. In early 2025, Zveare uncovered critical bugs in a major carmaker's dealer portal, enabling login bypass via client-side code manipulation to create a "national admin" account.[2][4] This allowed remote vehicle unlocking, engine starts, data lookups by VIN or name, and unauthorized account pairing—demonstrated ethically with a friend's consent.[4][5] The carmaker patched the issues within a week, confirming no prior exploitation.[4] He presented related findings at DEF CON 2025.[5] Zveare remains active in vulnerability research, emphasizing authentication flaws in APIs as key risks, with ongoing relevance in advancing secure connected vehicle tech amid rising autonomous driving adoption.[2][4]
Learn about the recent security vulnerabilities discovered in a carmaker's web portal and the potential consequences for customers.