• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Due to misconfigured server, CalAmp allows anyone to access account data
  • Data Leak

Due to misconfigured server, CalAmp allows anyone to access account data

Ddos May 21, 2018 3 minutes read

CalAmp Corp. is an Internet of Things solution provider headquartered in Irvine, California, providing back-office services for many well-known automotive anti-theft systems. Recently, security researchers have discovered that a server operated by CalAmp has misconfiguration issues, which has caused anyone to directly access and modify the database and even allow user accounts and vehicles to be taken over.

Security researchers Vangelis Stykas and George Lavdanis discovered this security vulnerability when searching for problems in the Viper SmartStart system, which allows users to remotely start, lock, unlock, or locate their vehicles directly from their smartphones, smartwatches, or wristbands.

The Viper SmartStart system application uses an SSL connection and prevents tampering by using SSL pinning. From this point of view, the application should have been very secure, but the researchers found that it not only connected to the mysmartstart[.]com domain name, but also connected to a third-party domain name (colt.calamp[.]com).

 

Obviously, this domain belongs to CalAmp. From the web content, this panel is a front-end called “Lender Outlook” service. The service is aimed at companies that have multiple Viper SmartStart system subaccounts and a large number of vehicles to enable more systematic management. Researchers used the user name and password of the Viper SmartStart system application to perform login attempts. It turns out that this is feasible.

Although all data in the domain is properly protected, all reports are provided by another server running Tibco JasperReports software. After deleting all the parameters, the researchers found that although the user account for the login is limited in authority, various reports can be accessed.

 

“We could not create a report or an adhoc or pretty much anything else, but we could copy paste existing ones and edit them so we can do pretty much anything. We could also edit the report and add arbitrary XSS to steal information but this was not something that we (or anyone in their right lawful mind) would want to do.”

Researchers also stated that as long as they know a user’s old password, they can use the Viper SmartStart system application to make password changes to fully take over the user’s account. Since the user can perform multiple operations on his car through the Viper SmartStart system, if the user account is taken over, the user may be taken over next.

The researchers reported this issue to CalAmp earlier this month and the company resolved the error within 10 days of receiving the report. In addition, they also updated their website to make it easier for security researchers to report on other vulnerabilities they discovered in their CalAmp products.

Source, Image: securityaffairs

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Microsoft workers uploaded sensitive login credentials to Microsoft’s own systems to GitHub
  2. 22,000 Suppliers Hit in Daikin Data Breach
  3. Fortinet Faces Potential Data Breach, Customer Data at Risk
  4. Jury Rules Against Google in $425M Privacy Lawsuit
  5. Plex Urges Password Reset After Data Breach
Tags: CalAmp

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.