A major automaker quietly patched serious security flaws in its dealership web portal earlier this year that could have allowed hackers to remotely unlock vehicles and access sensitive customer data, according to security researcher Eaton Zveare in an interview with TechCrunch.
Zveare, who works at software delivery company Harness, discovered the vulnerabilities during a weekend project. He told TechCrunch the bugs allowed him to create a “national admin” account granting unrestricted access to the automaker’s centralized dealer portal, which serves more than 1,000 dealerships across the United States.
With this level of access, a malicious actor could have viewed personal and financial customer information, tracked vehicles in real time, and even paired a car to a new mobile account — enabling remote functions such as unlocking doors from anywhere. In one test, conducted with a friend’s consent, Zveare successfully transferred control of a vehicle by simply attesting — without verification — that he was the legitimate owner.
The flaws, caused by buggy code loaded directly in the browser, allowed Zveare to bypass login security checks entirely. He said the portal also contained a national consumer lookup tool capable of identifying vehicle owners from a VIN or even just a name.
Beyond the data exposure, Zveare found that the interconnected dealer systems supported “user impersonation,” letting an admin account access other dealers’ systems without their credentials — a design he compared to vulnerabilities found in a Toyota dealer portal in 2023.
The automaker, which Zveare declined to name but described as widely known with several sub-brands, fixed the bugs within a week of his February 2025 disclosure. The company said it found no evidence the vulnerabilities had been exploited before his report.
Zveare warned that such dealership portals are “security nightmares waiting to happen” due to their broad access privileges and weak authentication practices. As he told TechCrunch: “Only two simple API vulnerabilities blasted the doors open — if you get authentication wrong, everything just falls down.”

