Security researchers have uncovered a flaw that can be used by hackers to accelerate or brake the Xiaomi electric scooter.
According to researchers at Zimperium, a potential hacker can be within 100 metres of the vehicle to carry out an attack, which could cause serious harm to the rider.
Electric scooters such as the Xiaomi product are highly popular among people living in built-up areas, offering an easy, cheap mode of transportation.
Researchers have released a proof-of-concept (PoC) for this particular attack method, which affects the M365 range of scooters. The PoC allowed the team to mount a denial-of-service attack and install firmware that can manipulate the scooter’s acceleration and braking capabilities.
The root cause of the vulnerability appears to be the scooter’s use of Bluetooth, which enables the rider to use a number of features, including a cruise-control feature, eco mode and an anti-theft system.
Recommended: 10 Trends Driving Cyber Security in 2019
Users can access such features by downloading a smartphone app, which creates password protection for each individual scooter.
“During our research, we determined that password is not being used properly as part of the authentication process with the scooter and that all commands can be executed without the password,” a company blog post read. “The password is only validated on the application side, but the scooter itself doesn’t keep track of the authentication state.”
According to the researchers, certain features can be used without authentication, which greatly increases the risk of attack. A video was also released by the team showing how their proof-of-concept could lock down a scooter by taking advantage of its anti-theft feature – without neither the user’s consent nor the need for authentication.
Xiaomi was contacted by the team and informed of the vulnerability, which the company then confirmed to be a known issue.
The firm gave no indication as to when the problem would be rectified, researchers noted. To prevent hackers from seizing control of the scooter, the team recommended that users connect their mobile app before use, and to keep the app connected throughout.
By doing this, attackers will be unable to remotely lock or install malware.






