Tata Motors Reportedly Patched E-Dukaan, FleetEdge Flaws After Researcher Discovered AWS Key Leak

Tata Motors patched the security flaws in 2023, shortly after they were discovered by a security researcher, according to a report.

Advertisement
Written by Dhruv Raghav, Edited by David Delima | Updated: 29 October 2025 11:46 IST
Highlights
  • Tata Motors' E-Dukaan is an online marketplace for spare parts
  • Tata Motors is one of India's largest automotive companies
  • The security flaws exposed AWS keys

Tata Motors fixed the security vulnerabilities in 2023

Photo Credit: Reuters

Tata Motors has fixed various vulnerabilities found in two of its public-facing websites in 2023, namely E-Dukaan and FleetEdge, according to a report. The issues were brought to light by a cybersecurity researcher, who recently shared details about the flaws. The researcher discovered the flaws in two Tata Motors-owned platforms in 2023. He claimed that the security vulnerability gave him access to the Amazon Web Service (AWS) keys, which could potentially allow a hacker to download company data and upload unauthorised files on Amazon's servers.

Tata Motors Identified, Fixed Security Vulnerabilities in 2023

In a blog post, security researcher Eaton Zveare revealed that he discovered various security vulnerabilities in Indian automotive giant Tata Motors' e-marketplace for spare parts, dubbed E-Dukaan, in 2023.

Advertisement

Another public-facing website that was found to be vulnerable to cyberattacks was FleetEdge, Tata Motors' fleet management and tracking solution. The researcher has shared details about the four most significant flaws that he came across on the website.

Tata Motors told TechCrunch that these reported vulnerabilities were identified and “fully addressed” in the same year.

Advertisement

Zveare highlighted that Tata Motors' E-Dukaan and FleetEdge revealed the AWS keys in plain text, which can be misused by bad actors to download a user's files hosted on Amazon's cloud service, “upload malicious content”, and accumulate large bills in server costs. Moreover, these consumer-facing websites are said to host more than 70TB of data with sensitive customer information.

The researcher also said that Tata Motors introduced a vulnerability in the data analytics tool Tableau, which gave backdoor access to the cybersecurity researcher. Zveare claims that he was able to log in as the server admin without a password, revealing details regarding “internal projects, financial reports, and dealer dashboards”.

Advertisement

The company also told TechCrunch that its cybersecurity infrastructure is audited at regular intervals by leading firms and that the firm maintains access logs to see whether somebody has managed to gain unauthorised access to its database. The automotive giant reportedly said that it actively works with industry experts and security researchers to strengthen its online infrastructure, while ensuring timely mitigation of cyberattacks.

Tata Motors is a leading vehicle manufacturer in India and the firm is also present in 125 countries, according to its website. It started with manufacturing commercial vehicles and later expanded into the passenger vehicles segment. It also commands a large four-wheeler electric vehicle (EV) market share in the country.

Advertisement

Most top-of-the-line variants of cars offer connected car features, providing location data, speed, and the owner's personal details on the owner's phone. This data is mostly routed through the company's servers. Hence, it becomes pertinent for automotive giants to timely identify and patch such flaws.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vi Introduces Rs 200 Pack With 20 OTT Platforms and Unlimited 5G
  2. Vivo S2 to Launch in India Soon, Design Officially Teased
  3. Exclusive: iQOO Z11 to Launch in India Soon With This MediaTek SoC
  4. Insta360 X6 Retail Box Leak Reveals Key Details Ahead of Launch
  5. Redmi Note 17 India Launch Teased; Price in India Leaked
  6. Poco M8 Power Set to Launch in India on This Date
  7. OPPO Reno16 Series: Is This the Complete Creator Device?
  8. Vivo T5e With a 5,500mAh Battery Debuts in India at This Price
  9. Flipkart Freedom Sale Starts August 8: Bank Offers and Deals Teased
  10. God of War Laufey Launches Next Year, New God of War With Kratos Confirmed
  1. Redmi Note 17, Note 17 Pro, Note 17 Pro Max European Prices Reportedly Leak Ahead of Launch
  2. Flipkart Freedom Sale Starts August 8: Bank Offers and Deals Teased
  3. Redmi Note 17 India Launch Teased; Price in India Leaked Online
  4. Blockaid Reports $450,000 Exploit as Garden Finance Disables App
  5. Oppo A7 Pro Max Officially Teased With Massive 10,000mAh Battery Ahead of Launch
  6. Rockstar Games Details GTA 6 Digital Download Code Region Restrictions
  7. Vivo S2 India Launch Confirmed as Official Teaser Goes Live: Expected Specifications, Features
  8. Adidas Hyperboost Edge Launched in India With Hyperboost Pro Foam, Lighttraxion Outsole Technology
  9. BitMart Exchange to Cease Trading by August 26, Full Shutdown Set for 2027
  10. Apple Watch Series 12, Watch Ultra 4 Might Sport a Similar Design as Last Year; Watch SE Refresh Unlikely in 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.