Tata Motors Said to Fix E-Dukaan and FleetEdge Vulnerabilities Following AWS Key Exposure
Tata Motors reportedly addressed several critical security flaws in two of its digital platforms — E-Dukaan and FleetEdge — following a disclosure from an independent cybersecurity researcher. According to the report, the vulnerabilities were identified in 2023 and were serious enough to potentially expose sensitive company data. The flaws were said to have revealed Amazon Web Services (AWS) access keys, which, if exploited, could have allowed attackers to download confidential information or upload malicious files to Tata Motors’ cloud servers.
Researcher Flags Data Exposure Risks
Cybersecurity researcher Eaton Zveare, who has previously reported vulnerabilities in major tech platforms, detailed his findings in a blog post published earlier this week. He claimed that Tata Motors’ E-Dukaan platform, the company’s e-commerce portal for vehicle parts, contained misconfigured access that exposed AWS credentials. These credentials, he explained, could have granted full access to the company’s cloud storage, including internal files and sensitive operational data.
FleetEdge Platform Also Found Vulnerable
In addition to E-Dukaan, Zveare also discovered flaws in FleetEdge, Tata Motors’ fleet tracking and management solution. The researcher identified four key vulnerabilities that could have allowed unauthorised users to access restricted data and system resources. He noted that the flaws could be exploited remotely, making them particularly dangerous if discovered by malicious actors.
Tata Motors’ Response and Remediation
Tata Motors was reportedly notified about the security lapses in 2023, and the company acted promptly to patch the exposed endpoints and revoke compromised AWS keys. Following internal investigations, both E-Dukaan and FleetEdge were updated with enhanced authentication and access control mechanisms. The automaker has not disclosed whether any data breaches occurred as a result of the vulnerabilities, but cybersecurity experts have praised the company for its swift response and transparency. The incident underscores the growing cybersecurity challenges facing large automotive companies as they continue expanding into connected and cloud-based services.



