Climate & Energy
Live WireRemote EV Shutdowns Expose India’s Connected Device Security Gap
This is worth watching because it affects how founders, investors, and operators read the next business cycle.

The shutdowns point to a widespread reliance on generic third-party BMS software without adequate authentication or access controls
The controversy also raises broader questions around data privacy as many BMS apps access and generate data such as GPS location, driver behaviour and vehicle usage patterns
The same concerns extend to the broader IoT ecosystem, especially imported and white-labelled devices
At the centre of the controversy are the BMS that communicate through widely used mobile applications such as BAT BMS, Lossigy and Epoch Li-ion, with a few of these apps being of Chinese origin. These apps connect to the BMS over Bluetooth, allowing users to monitor battery health, charge levels, voltage, temperature, and discharge behaviour.
A BMS is an embedded controller inside a lithium-ion battery pack that monitors these parameters while also preventing overcharging and overheating.
However, experts say the BMS installed in budget EVs lack adequate authentication mechanisms or rely on default access settings. Consequently, anyone within the Bluetooth range – typically 10-15 metres – can connect to the BMS using the aforementioned apps. Depending on the BMS configuration, users can view battery data or issue commands to disable the battery’s output, making the vehicle inoperable.
In simple terms, the person is not “hacking” in the conventional sense. Instead, they are exploiting weak access controls in the BMS for unauthorised access to features that affect the vehicle’s operations.
Experts say the episode exposes not only a cybersecurity weakness but also India’s dependence on opaque firmware embedded in imported hardware.
“The vulnerability isn’t in the app itself, which is a legitimate diagnostic tool; it’s in how battery vendors skipped access control on the BMS firmware,” said Ankush Tiwari, founder and CEO of cybersecurity intelligence provider pi-labs.
Cybersecurity experts Inc42 spoke to said the primary responsibility for securing access to the BMS rests with original equipment makers (OEMs) and battery suppliers.
Inc42 independently verified some of the OEMs whose vehicles could be controlled using the apps, including Yatri, Mayuri, Vande Bharat and City Life. Drivers using these vehicles said they relied on the BAT BMS app to monitor battery health.
Queries sent to these OEMs didn’t receive a response till the time of publication.
Notably, drivers across multiple brands were using the same application. Drivers of five-wheeler electric loaders also reported similar incidents, suggesting the issue extends beyond e-rickshaws. Experts say this points to a widespread reliance on generic third-party BMS software without adequate authentication or access controls.
The issue becomes more concerning in light of a GitHub post published several years ago that highlighted the weak authentication of some of these BMS apps and demonstrated how some of those protections could be bypassed.
“It is clear that these manufacturers didn’t do any due diligence before importing these batteries or distributing the app. Many of these components are easily available on platforms like Alibaba, where several OEMs source from. This is a road safety issue, and banning the apps is not the solution,” said cybersecurity analyst and ethical hacker Karan Saini.
Sourced from KnowledgeLoop
