🚨Cyber News - 900 Unsecured TeslaMate Servers Expose Real-Time Tesla Vehicle Data Globally
A cybersecurity researcher, Seyfullah KILIÇ, discovered that around 900 self-hosted TeslaMate instances are exposed online without authentication, leaking real-time Tesla vehicle data such as GPS coordinates, driving history, charging patterns, and software versions.
TeslaMate is an open-source tool that logs telemetry from Tesla’s official API and typically runs on port 4000, often with Grafana dashboards on port 3000. Many users deploy it on cloud servers without securing endpoints, making the data accessible to anyone on the internet.
The researcher created teslamap[.io to visualize the locations of exposed vehicles, revealing risks like tracking daily routines, residential addresses, and even vacation periods.
These exposures present severe physical security risks, especially since TeslaMate lacks default access control. The developers have acknowledged the flaw and plan to introduce authentication by default in future versions.