
A telematics control unit installed by dealerships in over 2 million US cars has critical vulnerabilities that allow remote attackers to control vehicle functions. IOActive researchers found weak security in the device's firmware and cloud backend. Owners are urged to check their vehicles and apply patches immediately.
Over 2 million vehicles across the United States harbor a secret that could put their drivers in grave danger. A small telematics control unit (TCU), installed by dealerships as part of optional tracking or alarm systems, contains multiple critical security vulnerabilities. These flaws allow remote attackers to unlock doors, start engines, track locations, and even disable braking or engine controls—all without the driver’s knowledge. Researchers from IOActive uncovered the weaknesses, which they detailed to Wired. The device remains active and connected to cellular networks even when the owner never subscribes to the service, making it a persistent and largely invisible attack surface. This oversight transforms a convenience feature into a significant cybersecurity liability. The findings were disclosed to the manufacturer, but the patch rollout faces significant obstacles.
The TCU is an aftermarket add-on, often fitted by dealerships to enable stolen vehicle recovery, remote start, and emergency assistance. But IOActive’s analysis revealed a litany of security lapses: weak authentication, hardcoded credentials, and insecure communication protocols between the device and its cloud backend. These issues mean that any attacker with network access can potentially compromise the device and, through it, the vehicle’s critical systems.
Joe Schallan, a senior security consultant at IOActive, called it “a massive oversight.” He told Wired: “The device was meant to be an optional feature, but it’s actually a gateway for hackers to control almost every function of a car.”
The device connects to the vehicle’s Controller Area Network (CAN) bus, the internal network that governs everything from airbags to brakes. Once an attacker takes control of the TCU, they can inject malicious CAN messages, effectively overriding the driver’s commands. The insecurity is compounded by the fact that many dealers do not inform buyers about the device or its capabilities. It remains dormant in the car, silently connected to the internet, awaiting instructions.
Further analysis revealed hardcoded credentials embedded directly in the device’s firmware. These credentials allowed direct access to the cloud backend, making it possible for an attacker to interact with any device from the same vendor. The communication between the device and the cloud used unencrypted HTTP, meaning that anyone with network visibility could intercept commands and data.
To understand the risk, consider a typical attack scenario. The attacker first identifies a vulnerable TCU by scanning for devices that respond on specific ports. Using exploit code that targets the weak authentication or leveraging the hardcoded credentials, they gain administrative access. From there, they can:
Because the device communicates over the cellular network, the attacker can be anywhere in the world. The lack of encryption and weak credential management makes these attacks relatively straightforward. Worse, the cloud backend itself was found to be vulnerable, enabling an attacker to issue commands to many vehicles at once, potentially causing widespread disruption.
Sam Hodges, another IOActive researcher, emphasized the urgency: “The patch needs to be applied urgently, but because the device is hidden and many owners don’t know it exists, the risk remains high for months or even years.”
In total, IOActive estimates that more than 2 million vehicles in the US are equipped with the vulnerable device. The researchers tested a sample of devices and found that 100% contained at least one critical vulnerability enabling full remote compromise. This is not a niche issue—it affects a wide range of popular car models from multiple manufacturers. The device is sold by various aftermarket suppliers and installed at dealerships, meaning the vulnerability crosses brand boundaries.
| Statistic | Detail |
|---|---|
| Estimated affected vehicles | Over 2 million |
| Percentage of devices with critical flaws | 100% |
| Types of control possible | Doors, engine, brakes, location tracking |
| Source | Wired (citing IOActive research, 2024) |
These numbers highlight a systemic failure in automotive cybersecurity. Aftermarket devices are often not subject to the same level of security scrutiny as original equipment. Additionally, the long lifecycle of a vehicle means that unpatched devices could remain in service for years. The IOActive researchers tested devices from multiple vendors, and all exhibited similar weaknesses, indicating that this is an industry-wide problem.
One of the most troubling aspects of this vulnerability is the difficulty of patching. Unlike a smartphone or computer, a car’s TCU may not receive over-the-air updates. Many devices require physical access to update firmware. Even if a patch is developed, notifying and reaching all affected owners is a huge challenge. The device is often buried deep in the dashboard, invisible to the car owner.
Moreover, the company that manufactured the TCU may not have a direct relationship with the car owner—the dealer is the intermediary. If a dealer goes out of business or fails to communicate the risk, the vulnerability persists. Joe Schallan noted that many owners are completely oblivious: “They don’t know this device is in their car, and no one is reaching out to them.”
The patch itself must be applied to each device individually, possibly requiring a visit to the dealership. With over 2 million units distributed across the country, the logistics are daunting. Without a coordinated recall or mandatory update, many vehicles will remain exposed.
While the onus should be on manufacturers and dealers to fix the problem, car owners can take steps to protect themselves:
Some owners may be charged for removal, but the security benefit likely outweighs the cost. Automakers and regulators should make it mandatory to disclose all internet-connected devices in vehicles. Security flaws must be reported, and patches issued in a timely manner. Owners deserve to know what’s hidden in their cars.
This vulnerability is part of a broader trend. According to research, automotive cybersecurity vulnerability disclosures have risen by 30% in the last two years. As cars become more connected, the number of potential attack surfaces increases. Meanwhile, the prevalence of dealer-installed aftermarket telematics devices has remained stable over the last five years, meaning that many vehicles on the road carry this hidden risk.
The industry needs to adopt a security-first mindset. Every component with network connectivity should undergo rigorous security testing. Standards for aftermarket devices should be as strict as those for original equipment. Regulators must step in to ensure transparency and accountability. In Europe, UN Regulation 155 mandates cybersecurity measures for vehicle types, but similar regulations are not yet widespread in the US. This vulnerability underscores the need for legislative action.
The telematics control unit hidden in millions of US cars represents a clear and present danger to drivers. With 100% of tested devices found to be critically vulnerable, the potential for widespread exploitation is real. Car owners must act now to determine if they are affected and demand patches from dealers. Cybersecurity cannot be an afterthought in the automotive industry—especially when lives may depend on it. The device may be out of sight, but the risk should not be out of mind. For the industry, this is a call to secure not just the cars they build, but every component that connects to them.



A telematics control unit (TCU) is an aftermarket device that provides features like GPS tracking, remote start, and emergency assistance. It connects to your car's internal network (CAN bus) and maintains a constant cellular link to the cloud. Researchers at IOActive discovered critical security flaws—such as weak authentication and hardcoded credentials—that let remote attackers take control of vehicle functions.
Check for a small box under the dashboard or in the trunk, often connected to the vehicle's diagnostic port. You can also review your car's documentation for references to a telematics or tracking system. If you're unsure, your local dealer can tell you whether such a device was installed as part of an optional package.
Once inside the TCU, an attacker can send malicious commands over the CAN bus to unlock doors, start the engine, disable brakes, or even cut the engine while driving. They can also track your location in real time. This turns a convenience feature into a dangerous security risk.
The device is designed to maintain its cellular connection even if you never activate the service, because it used by dealerships for inventory tracking or as a sales tool. Researchers found that the device remains online and able to receive commands from the cloud at all times. This means it can be targeted by remote attackers even if you never use its features.
First, check with your dealer to see if your vehicle is affected and if a patch is available. If a fix exists, apply it immediately. If not, you can physically disconnect the device by pulling its fuse or having a mechanic unplug it, but that may disable legitimate features like emergency call systems.