For Business

Xiaomi M365 scooters can be hacked and managed remotely

Xiaomi M365 electric scooters are vulnerable – the security problem in these vehicles was discovered by expert Reni Idan from Zimperium, a company that sells exploits. The gap is so serious that it can allow an attacker to remotely control electric scooters – suddenly slow down or accelerate the vehicle.

The problem lies in the way Xiaomi M365 users are authenticated. Passwords required for authentication in the scooter system are used incorrectly, since they are checked only on the application side.

The scooter itself does not monitor the authentication process, which leads to a serious bug – all commands can be executed without the need to enter a password.

To demonstrate the vector of attack, the researcher first conducted a DoS attack on the M365, and then prepared the foundation for installing a malicious version of the firmware, which allows you to gain complete control over the scooter.

Zimperium has even created a special proof-of-concept code in the form of a malicious application. This application can search for nearby Xiaomi M3656, and then exploit the vulnerability found in these devices.

At the very process of the attack can be viewed in the video, which we present below:

User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Remove Thenetaservices pop-up ads (Virus Removal Guide)

Thenetaservices.com is a site that tries to force you into clik to its browser notifications…

8 hours ago

Remove Litdeetar.live pop-up ads (Virus Removal Guide)

Litdeetar.live is a domain that tries to trick you into subscribing to its browser notifications…

8 hours ago

Remove Bugracibs.xyz pop-up ads (Virus Removal Guide)

Bugracibs.xyz is a site that tries to force you into clik to its browser notifications…

8 hours ago

Remove Colidunt.xyz pop-up ads (Virus Removal Guide)

Colidunt.xyz is a domain that tries to trick you into clik to its browser notifications…

1 day ago

Remove Myflisblog pop-up ads (Virus Removal Guide)

Myflisblog.com is a site that tries to trick you into subscribing to its browser notifications…

1 day ago

Remove Dofenpas.xyz pop-up ads (Virus Removal Guide)

Dofenpas.xyz is a domain that tries to trick you into subscribing to its browser notifications…

1 day ago