# Compromising Honda's power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API

DevFeed: [Compromising Honda's power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API](<https://devfeed.tech/articles/compromising-honda-s-power-equipment-marine-lawn-garden-dealer-ecommerce-platform-through-a-vulnerable-password-reset-api-32604.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/06/06/honda-ecommerce-hack/>)

Author: Eaton

Published: 2023-06-06T15:33:57Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Website](<https://devfeed.tech/topics/website.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [data](<https://devfeed.tech/tags/data.md>), [ecommerce](<https://devfeed.tech/tags/ecommerce.md>), [password-reset](<https://devfeed.tech/tags/password-reset.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [website](<https://devfeed.tech/tags/website.md>)

## AI overview

A writeup describes compromising Honda's power equipment, marine, and lawn-and-garden dealer eCommerce platform through a vulnerable password reset API and broken access controls. The reported access included customer orders, dealer websites and accounts, email records, and potentially payment-related keys and internal financial reports. The incident did not affect Honda's automobile business.

## Source excerpt

A vulnerable password reset API made it possible to take over any account and gain admin-level access to the platform. In addition, broken/missing access controls made it possible to access all data on the platform.