ADVERTISEMENT

Researchers Comment that Chinese-made GPS Device Has Cyberattack Risks

MiCODUS was contacted by the Associated Press about the matter. However, it reported that they did not receive an answer.

CISA stated in a statement, that it didn’t know of any “active exploit” of these vulnerabilities.

Globally, GPS trackers are used to monitor vehicle groups from trucks to school buses and military vehicles. These devices can also be used to protect vehicles from theft or loss.

Many devices can collect data about vehicle tracking and also examine driver and vehicle actions. These data could include driver behavior or fuel consumption. Many devices can control the vehicle’s fuel, locking system and other functions.

ADVERTISEMENT

MiCODUS claims that approximately 1.5 million devices have been used by 420,000 customers.

BitSight stated that a cyberattacker can remotely disconnect the fuel line from a vehicle by using the MV720 device. Pedro Umbelino, BitSight researcher, stated that an attacker could also see the location of a vehicle in real time for spying purposes.

BitSight discovered that the device comes with a default username that more than 90% of users don’t change. BitSight also found security flaws in the software used by the web server to control devices via the internet.

BitSight reported that its research revealed that a major energy company, an aerospace company, and national militaries from South America and Eastern Europe were among the customers. Other customers included a nuclear power plant operator, and a Western European national law enforcement agency. BitSight didn’t name any of these companies. The countries with the highest number of users were Brazil, Mexico and Spain.

Richard Clarke was a former U.S. cybersecurity chief. According to Clarke, he doesn’t believe that the device was intended to be used maliciously in China by the government. However, that is still possible.

Clarke stated that the Chinese companies are legally required to comply with their government’s orders, which is a real threat. Clarke stated, “You just wonder how often we will find these things infrastructure where there’s a potential to Chinese abuse – and the users don’t know?”

<< Previous

ADVERTISEMENT