Skip advert
Advertisement

Mitsubishi Outlander PHEV at risk of hacking

Security experts showed how hackers and thieves can exploit a weakness in the Mitsubishi Outlander PHEV's Wi-Fi system to disarm the alarm

Mitsubishi Outlander PHEV - front

The Mitsubishi Outlander PHEV - UK's best selling plug-in electric car - has become the latest car susceptible to hacking, after weaknesses in the car's on-board Wi-Fi security allowed researchers to turn off security alarms.

Security expert Ken Munro and his colleagues at Pent Test Partners security firm began investigating the Outlander PHEV after Munro noticed the mobile app used to communicate with the car had an unusual characteristic.

Advertisement - Article continues below

Most mobile apps use a GSN module to communicate between the car and the mobile phone, but the Outlander PHEV does without one. Instead, the Mitsubishi has a wireless access point on-board the car, which means it can be talked to directly.

Munro then realised the password to the Wi-Fi key can be easily cracked. He said: “The password is not long enough. The format is four lower cases, plus six numeric digits. That just isn’t enough.” On a relatively slow cracking rig, it took Munro and his team just four days to crack the password key. With top notch software the key can be accessed within a day. 

Munro then looked if there was any more security between phone and the Wi-Fi access point other than the key. He said: “ We listened to look at the traffic going between the car and the device, and discovered a relatively simple binary protocol that was incredibly straightforward to understand and reverse engineer.”

This allowed Munro to communicate with the car directly, and gave him control of functions like lights and air-conditioning, and more worryingly, access to the charging and security status. Munro was able to turn off the car’s alarm and disconnect it from charging, showing how potential perps could break into the car and drive away with it. 

A short-term fix exists, according to Munro. He advises to first unpair all mobile devices that have been connected with the car's access point. Then, using the app, he advises users to go to 'Settings' and select 'Cancel VIN registration', to effectively put the device to sleep. A long-term fix would require intervention from Mitsubishi. 

Mitsubishi has since said it has taken the “matter seriously". It also pointed out that the hack affects the car's app and gives hackers limited access: “It should be noted that without the remote control device, the car cannot be started and driven away." 

Are you worried about car hackers? Tell us in the comments below...

Skip advert
Advertisement
Skip advert
Advertisement

Recommended

Kia UK boss calls for clear ZEV roadmap, plus “modest” consumer incentives
Kia's UK boss, Paul Philpott standing next to a Kia EV6

Kia UK boss calls for clear ZEV roadmap, plus “modest” consumer incentives

Brand CEO says ZEV mandate is a threat, asking for clarity from the Labour government
News
6 Jan 2025
Car finance scandal: Supreme Court hearing could halve number of claimants
Finance contract, car key and calculator on desk

Car finance scandal: Supreme Court hearing could halve number of claimants

Scandal involving car finance commission could see motorists entitled to billions of pounds in payouts
News
19 Dec 2024
Dieselgate is back! Thousands of cars could be recalled as scandal returns
Emissions tests questioned

Dieselgate is back! Thousands of cars could be recalled as scandal returns

The DfT is currently investigating as many as 47 models across several brands that are suspected to use diesel defeat devices
News
14 Nov 2024
MoT failure rate is worse for vans than cars
MOT

MoT failure rate is worse for vans than cars

More than a third of light commercials failed their first MoT last year, new figures show
News
12 Nov 2024

Most Popular

Car brands with the most recalls: BMW tops the UK recall chart in 2024
BMW 530e - front cornering

Car brands with the most recalls: BMW tops the UK recall chart in 2024

Did you receive a letter alerting you to a potentially dangerous car fault? Here are the car brands that sent the most out
News
17 Jan 2025
Lexus planning a thrilling new range of ultra high-performance models
Lexus LBX Morizo RR - dynamic front 3/4

Lexus planning a thrilling new range of ultra high-performance models

The long-lived RC F will be axed this year, but Lexus is set to unleash a new wave of exciting new performance-focused cars
News
17 Jan 2025
EV discounts: are they a short-term solution with long-term problems?
Vauxhall Corsa Electric front corner driving

EV discounts: are they a short-term solution with long-term problems?

Optimistic residual value projections for EVs have left vehicle leasing firms “millions and millions” out of pocket
News
18 Jan 2025