Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

IoT Security

Misconfigured TeslaMate Instances Put Tesla Car Owners at Risk

Attackers can find tons of information on Tesla cars and their drivers by searching for misconfigured TeslaMate instances online.

Tesla hack

Misconfigured TeslaMate instances can leak tons of data on the internet, potentially exposing Tesla cars and their drivers to malicious attacks, IoT security intelligence firm Redinent reports.

A third-party data logging application, TeslaMate relies on the Tesla API to retrieve various types of information about Tesla cars, making it available to users on their computers.

While the application is a great tool for keeping track of car data, it also poses a significant risk if improperly configured, Redinent has discovered.

Various types of information about the application can be found online by searching for images with the ‘teslamate configure’ tags, but attackers can also use specialized search engines and specific queries to identify misconfigured TeslaMate instances and access information without authorization.

Using Censys’ search service, Redinent has identified more than 1,400 misconfigured instances that allow access without authentication.

An attacker could perform this operation to access a car’s live location, check whether the vehicle is locked and whether the driver is present, and even make an online car go to sleep, the security firm says.

Advertisement. Scroll to continue reading.

The issue, Redinent notes, is that users often do not configure this third-party software correctly, which leads to privacy breaches and other types of risks by allowing unauthorized access to Tesla car data.

Furthermore, an attacker could “set virtual boundaries around the car and receive alerts, potentially compromising the owner’s daily routine and posing risks like planned robberies or other malicious activities,” Redinent notes.

Responding to a SecurityWeek inquiry, Redinent security researcher Souvik Kandar said the vulnerability has been reported to TeslaMate.

“But the vulnerability arises due to misconfiguration on the user’s end. Teslamate is not at fault here,” Kandar said.

Related: Tesla Discloses Data Breach Related to Whistleblower Leak

Related: Tesla Sued Over Workers’ Alleged Access to Car Video Imagery

Related: Tesla Retail Tool Vulnerability Led to Account Takeover

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.