The Xiaomi M365 scooter 2019-02-12 prior to 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands include suddenly braking, locking, and unlocking.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mi m365_firmware |