Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » GPS Sinotrack GPS devices are vulnerable to distance driving through default passwords
Global Security

GPS Sinotrack GPS devices are vulnerable to distance driving through default passwords

AdminBy AdminJune 11, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 11, 2025Red LakshmananIoT / vulnerability security

On the GPS Sinotrack GPS devices, two safety vulnerabilities were opened that can be used to control certain remote features on connected vehicles and even track their places.

“Successful operation of these vulnerabilities can allow the attacker to access devices without permission through the overall Internet management interface,” Cybersecurity and US Infrastructure (CISA) (CISA) Agency (CISA) – Note In advisory.

“Access to the device profile can allow the attacker to perform some distant features on connected vehicles such as tracking the vehicle and shutdown on the fuel pump where it is maintained.”

Cybersecurity

The vulnerabilities according to the agency affect all versions of the PC Sinotrack IoT platform. A brief description of the disadvantages below –

  • Cve-2025-5484 (CVSS Assessment: 8.3) – Simy authentication in the central interface control interface Sinotrack stems from the default password and username, which is an identifier printed on the receiver.
  • Cve-2025-5485 (CVSS assessment: 8.6) – Username used for authenticity in the web management interface, that is, the ID, is a numerical value of no more than 10 digits.

The attacker can obtain devices IDs either with physical access or fixing identifiers from devices located on publicly available sites such as eBay. In addition, the opponent can list potential targets by increasing or reducing known identifiers either by listing random digital sequences.

“Due to the lack of security, this device allows the remote performance and control of the vehicles to which it is linked, as well as stealing sensitive information about you and your vehicles,” said Raul Ignasio Cruce Security Researcher Jimenes, who reported the shortcomings of CISA, said The Hacker News.

Cybersecurity

There are currently no corrections that decide vulnerabilities. The Hacker News turned to Sinotrack for comments and we will update the story when we hear back.

In the absence of a patch, the users are advised to change the default password as soon as possible and take the ID. “If the sticker is visible in the available photos, think about removing or replacing the images to protect the ID,” Cisa said.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025

AI AI agents work on secret accounts – learn how to fasten them in this webinar

June 12, 2025

Zero Press AI Vulnerability exposes Copilot Microsoft 365 data without interaction with users

June 12, 2025

Connecting to Turn Signing Signing Code Screenconnect with -wit security risks

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025

AI AI agents work on secret accounts – learn how to fasten them in this webinar

June 12, 2025

Zero Press AI Vulnerability exposes Copilot Microsoft 365 data without interaction with users

June 12, 2025

Connecting to Turn Signing Signing Code Screenconnect with -wit security risks

June 12, 2025

More than 80,000 Microsoft Entra ID credits, directed using an open source Teamfiltration tool

June 12, 2025

Former Black Basta Members use Microsoft teams and Python scripts in 2025

June 11, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.