600,000 GPS trackers left exposed online with a default password of '123456'
Avast researchers said they found these issues in T8 Mini, a GPS tracker manufactured by Shenzhen i365-Tech, a Chinese IoT device maker.
Avast said the issues also impacted over 30 other models of GPS trackers, all manufactured by the same vendor, and some even sold as white-label products, bearing the logos of other companies.
A hacker can launch automated attacks against Shenzhen i365-Tech's cloud server by going through all user ID's one by one, and using the same 123456 password, and take over users' accounts.
Unfortunately for everyone, the issue persists to this day, as Shenzhen i365-Tech did not respond to Avast's emails when the company tried to warn the vendor. Similar contact attempts made by ZDNet's sister site CNET didn't succeed either.