# Vulnerabilities in a centralized automaker dealer platform enabled access to more than 1,000 US dealerships

DevFeed: [Vulnerabilities in a centralized automaker dealer platform enabled access to more than 1,000 US dealerships](<https://devfeed.tech/articles/def-con-33-how-i-hacked-over-1-000-car-dealerships-across-the-us-32615.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/13/def-con-33/>)

Author: Eaton

Published: 2025-10-13T15:13:09Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [account](<https://devfeed.tech/topics/account.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [automotive-industry](<https://devfeed.tech/tags/automotive-industry.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [us](<https://devfeed.tech/tags/us.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The article describes two vulnerabilities in a top automaker's centralized dealer platform: missing invite-token verification and a missing privilege check in account creation. The author states that these flaws enabled creation of a national admin account with access to systems across more than 1,000 US dealerships.

## Source excerpt

On August 10, 2025 at DEF CON 33 in Las Vegas, I presented what could possibly be the biggest vulnerability I may ever discover in the automotive industry. Read and watch how I managed to take over a top automaker's entire dealer ecosystem.