MyCar is a small aftermarket telematics unit from AutoMobility Distribution Inc. MyCar add smartphone-controlled geolocation,remote start/stop and lock/unlock capabilities to a vehicle with a compatible remote start unit. The MyCar Controls mobile application contains hard-coded admin credentials(CWE-798)which can be used in place of a user’s username and password to communicate with the server endpoint for a target user’s account. This vulnerability affects versions prior to 3.4.24 on iOS and prior to 4.1.2 on Android.

%d bloggers like this: