Smart Bus Smart Hacking: Free WiFi to Total Control
Kai Ching Wang, Chiao-Lin Yu (Senior Security Researcher · TMicro Taiwan)
DEF CON 33 · Day 1 · Main Stage
Overview
In an era where smart infrastructure is rapidly integrating into daily life, the security implications of these interconnected systems often lag behind their convenience. This talk, "Smart Bus Smart Hacking: Free WiFi to Total Control," delivered by Chiao-Lin Yu (Stephen Meow) and Kai Ching Wang (Canniver) at DEF CON, unveils a chilling reality: the ubiquitous free Wi-Fi on modern smart buses can be a direct conduit to gaining complete control over the bus's critical operational systems and even its central control infrastructure. The speakers meticulously detail a journey from a casual Wi-Fi connection during a traffic jam to uncovering a cascade of vulnerabilities that expose not just a single vehicle, but potentially an entire fleet.

Key moments
- 0:00 Introduction: Hacking a smart bus via free Wi-Fi
- 2:20 Explaining the Smart Bus System: ADAS and APS
- 6:30 First Hack: Exploiting the M2M Router via Free Wi-Fi
- 8:15 Full Router Control: Bypassing the Hidden Password
- 9:15 Escalating Access: SSH and Command Injection Vulnerability
- 10:15 Total Control: Live GPS and Sending Commands via MQTT
- 10:55 Shocking Revelation: Officially Certified, Yet Insecure Devices
Smart Bus Smart Hacking: Free WiFi to Total Control
Speakers: Chiao-Lin Yu (Stephen Meow), Senior Security Researcher, TMicro Taiwan; Kai Ching Wang (Canniver), Deputy Manager, CHT Security
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=AOp0QtUORBc
Overview
In an era where smart infrastructure is rapidly integrating into daily life, the security implications of these interconnected systems often lag behind their convenience. This talk, "Smart Bus Smart Hacking: Free WiFi to Total Control," delivered by Chiao-Lin Yu (Stephen Meow) and Kai Ching Wang (Canniver) at DEF CON, unveils a chilling reality: the ubiquitous free Wi-Fi on modern smart buses can be a direct conduit to gaining complete control over the bus's critical operational systems and even its central control infrastructure. The speakers meticulously detail a journey from a casual Wi-Fi connection during a traffic jam to uncovering a cascade of vulnerabilities that expose not just a single vehicle, but potentially an entire fleet.
The presentation highlights the profound risks associated with poorly secured Internet of Things (IoT) devices in public transportation. By demonstrating how easily an attacker could exploit common misconfigurations, weak passwords, and unencrypted communications, Yu and Wang reveal a significant security gap in systems designed to enhance safety and efficiency. This research is critical for transportation authorities, manufacturers, and security professionals, serving as a stark reminder that convenience must never come at the expense of robust security, especially when human lives and public safety are at stake. The talk underscores the urgent need for a paradigm shift in how smart transportation systems are designed, deployed, and secured against increasingly sophisticated, yet often surprisingly simple, attack vectors.
Background
▶ Watch: Introduction: Hacking a smart bus via free Wi-Fi (0:00)
Modern public transportation, particularly smart buses, relies on a complex network of interconnected technologies to improve safety, efficiency, and passenger experience. Two primary systems underpin this transformation: Advanced Driver-Assistance Systems (ADAS) and Automated Passenger Systems (APS). ADAS, as detailed by the speakers, functions as a vigilant co-pilot, utilizing an array of sensors, cameras, and radar to collect real-time data from the road. Its purpose is to provide safety support, warn drivers about potential hazards like pedestrians or proximity to other vehicles, and even monitor driver behavior for signs of fatigue or distraction. While ADAS enhances driver awareness and helps prevent accidents, it does not replace the human driver—at least not yet.
Complementing ADAS is the APS, which serves as the central nervous system connecting various components of the bus ecosystem. This includes linking individual buses to central control centers, station signs, passenger applications, and websites. APS manages bus schedules, monitors operational status, facilitates passenger convenience, and enables emergency response. The integration of ADAS and APS, while beneficial, creates a sprawling attack surface. The speakers identified four main types of terminals within this ecosystem: onboard terminals (GPS tracking devices), user terminals (passenger apps), roadside terminals (LED signs at bus stops), and central terminals (main servers that store data, control buses, and connect the entire system). All these components communicate through a network, often relying on a specialized piece of hardware at the heart of the bus's connectivity: the M2M (Machine-to-Machine) router. This powerful device, equipped with 4G and 5G capabilities, enables remote control, device checks, and updates, making it a critical, yet often overlooked, point of vulnerability within the smart bus architecture. The speakers' journey into hacking the bus began by exploiting the very convenience offered by this interconnected ecosystem, starting with the seemingly innocuous free Wi-Fi provided by the M2M router.
Key Findings
▶ Watch: First Hack: Exploiting the M2M Router via Free Wi-Fi (6:30)
The research uncovered a series of critical vulnerabilities that, when chained together, provided attackers with extensive control over individual buses and the broader smart transportation network. The initial point of entry was the bus's free Wi-Fi, which provided direct access to the M2M router. The router, running an old and simple BOA web server, was susceptible to a publicly known authentication bypass CVE, allowing the researchers to gain initial access without credentials. Further investigation revealed a hidden password field on the router's configuration page, easily exposed via browser developer tools (F12), granting full administrative control.
With router access, a subsequent port scan revealed an open SSH service, which the researchers exploited using the newly discovered credentials. This led to the discovery of a command injection vulnerability, providing a remote shell. Crucially, within the system commands, the researchers found plain-text credentials for the MQTT broker. Connecting to this broker allowed them to access live GPS data from the bus and, more alarmingly, send commands to other devices on the network, effectively turning the bus's control room into their playground. The speakers noted the irony that this M2M device had passed official security certification in Taiwan despite these glaring weaknesses.
Expanding their reconnaissance, the researchers scanned the router's DHCP table and identified an IP address from a different subnet, leading them to a Digital Video Recorder (DVR) device. This DVR, part of the ADAS system, was secured with trivial default credentials (admin/admin), granting access to live video feeds of the driver. Within the DVR's interface, another command injection vulnerability was found via its built-in ping tool. This consistent pattern of weak security extended to another platform configuration page discovered through the DVR, which also used default credentials (admin/admin), providing further access to the broader system.
The most alarming findings emerged from monitoring the network traffic. The ADAS web interface was found running on port 80 using unencrypted HTTP, a significant security oversight for a safety-critical system. A directory scan of this interface revealed:
/m: A dashboard displaying live status, location, and speed for all buses in the company's fleet, accessible without authentication./console: An administrative page allowing system setting changes, also exposed./media: A folder containing numerous video recordings from the buses, freely accessible./api/otp: An Open Trip Planner (OTP) route API, providing unauthenticated access to route information.
Further traffic analysis uncovered an entirely separate API help page on another IP address, again with no authentication or tokens required. This fully open API exposed critical functions like route management, master API calls, and ticket lists. The data from this API directly correlated with the live bus, including its speed, location, and even the driver's name, confirming it was a live production system, not a test environment. Finally, the researchers identified UDP packets related to the APS system. By referencing industrial standards, they could decode these packets and, more critically, craft fake packets to manipulate the bus's reported GPS location (e.g., placing it in the middle of the Pacific Ocean) or trigger emergency help signals. This demonstrated the potential for severe disruption and safety hazards, all stemming from a lack of encryption and authentication in the system's core communications.
Technical Deep Dive
▶ Watch: Full Router Control: Bypassing the Hidden Password (8:15)
The technical exposition began with the seemingly innocent act of connecting to the free Wi-Fi on the bus, which immediately provided network access to the internal bus systems. The first target identified was the M2M router, a central component for bus connectivity. Upon accessing its web interface, the researchers encountered a login page. While default passwords failed, an examination of the server details revealed it was running BOA, an antiquated and notoriously insecure web server. As highlighted in the talk, BOA is "king of the legend" in IoT hacking due to its vulnerabilities. The researchers leveraged a publicly known authentication bypass CVE for BOA, allowing them to circumvent the login page and gain access to the router's settings.
Even after this initial bypass, a hidden password field was discovered within the router's configuration page. A quick inspection using browser developer tools (F12) revealed the actual administrative password directly in the HTML source code, granting full administrative control over the router. This level of access allowed for comprehensive port scanning (implied to be using tools like Nmap) of the device, which unveiled an open SSH service on port 22. Using the newly acquired credentials, the researchers successfully established an SSH connection, gaining a remote shell to the router. Within this SSH environment, a command injection vulnerability was found, allowing arbitrary command execution. This is a critical vulnerability often exploited by injecting shell metacharacters (e.g., ;, &, |) into user-supplied input fields, such as a diagnostic ping utility, to execute additional commands on the underlying operating system.
A deeper dive into the router's system commands revealed the username and password for the MQTT (Message Queuing Telemetry Transport) broker. MQTT, a lightweight messaging protocol, is widely used in IoT environments for communication between devices. With these credentials, the researchers could connect to the MQTT broker, effectively "walking into the bus control room." This granted them the ability to observe live GPS data streams from the bus and, more critically, send commands to other connected devices. The implications of this are profound, as MQTT often serves as the backbone for remote control and data telemetry in smart systems.
From the compromised M2M router, the researchers began to map the internal network by examining the router's DHCP table, which lists all devices connected to the network and their assigned IP addresses. This led to the discovery of an IP address belonging to a different subnet, which, when accessed via a web browser, revealed a login page for a Digital Video Recorder (DVR). This DVR, an integral part of the ADAS system, was found to be protected by default credentials (admin/admin). Gaining access to the DVR allowed the researchers to view live video feeds from within the bus, monitoring the driver's activities. Within the DVR's administrative interface, another command injection vulnerability was identified through a diagnostic ping tool, reinforcing the pattern of insecure development practices.
Further exploration from the DVR led to the discovery of a platform configuration page, which served as a control panel for a larger system. Predictably, this interface also succumbed to default credentials (admin/admin), indicating a systemic failure in security across multiple devices within the smart bus infrastructure.
With extensive access to the M2M router, the researchers could now monitor the entire network's traffic. They observed data flowing to an ADAS web interface that was running on port 80 and utilizing unencrypted HTTP. This meant all communications, potentially including sensitive operational and personal data, were transmitted in plain text, making them vulnerable to interception and manipulation. A directory scan (akin to using tools like DirBuster or GoBuster) on this web server exposed several critical, unauthenticated endpoints:
/m: A dashboard providing real-time status (location, speed) for all buses in the fleet, not just the single compromised bus./console: An administrative interface that allowed viewing and changing system settings./media: A directory containing numerous recorded video footages from the buses, accessible to anyone who knew the URL./api/otp: The Open Trip Planner (OTP) route API, which provided unauthenticated access to route planning functionalities.
This initial discovery led to an even more significant finding: another IP address within the monitored traffic stream led to a full API help page that was completely unauthenticated. This API, described as "hacker-friendly," provided full access to various functions including the route API, master API, and ticket lists, without requiring any login, tokens, or secret keys. The data exposed through this API was validated against the actual bus the researchers were on, confirming it was a live, production system, even displaying the driver's name.
Finally, the research delved into the APS system's UDP packet communication. The researchers identified specific UDP packets being transmitted and, by referencing industrial standards used in Taiwan (such as an "ST monitor script"), they were able to decode the packet structure, extracting information like GPS data and average speed. This understanding of the packet format enabled them to demonstrate the ability to craft fake UDP packets via a Man-in-the-Middle attack. This could allow an attacker to spoof the bus's location (e.g., making it appear in the Pacific Ocean) or even trigger false emergency signals, highlighting the severe safety implications of unauthenticated and unencrypted industrial control communications. The speakers even quipped that ChatGPT could write a script to decode these packets, underscoring the ease with which such an attack could be orchestrated.
Demo / Proof of Concept
▶ Watch: Total Control: Live GPS and Sending Commands via MQTT (10:15)
The presentation served as a comprehensive proof of concept, detailing the step-by-step exploitation of the smart bus system. While the speakers explicitly stated they avoided a live demonstration that could lead to an actual accident, they provided compelling evidence and screenshots throughout the talk to illustrate each stage of the attack chain.
The M2M router exploitation was demonstrated by showing the web login page, the use of a public CVE for BOA to bypass authentication, and the subsequent revelation of the hidden password via browser developer tools. Screenshots confirmed access to the router's administrative interface. The SSH access was evidenced by showing a command-line interface, and the discovery of MQTT credentials was highlighted by displaying the system command output where they were found in plain text. Connecting to the MQTT broker was then demonstrated through a screenshot of the broker's output, revealing live GPS data from the bus and the ability to send commands.
For the DVR exploitation, the researchers presented screenshots of the DVR's login page, emphasizing the use of default credentials (admin/admin). Once authenticated, a screenshot displayed the live video feed from inside the bus, demonstrating direct surveillance capabilities. The discovery of the command injection vulnerability within the DVR's ping tool was also outlined, showing how simple diagnostic functions could be abused. Similarly, access to the ADAS/APS platform was shown through its login page and the successful authentication using default credentials.
The most impactful demonstrations involved the network traffic analysis. The presentation included screenshots of the unencrypted HTTP ADAS web interface and the results of a directory scan. These visuals showed the /m dashboard with real-time data for all buses, the /console administration page, and the /media folder containing numerous unauthenticated video recordings. The exposure of the Open Trip Planner API was also visually confirmed. Furthermore, the discovery of the fully open API help page was highlighted with screenshots of the extensive, unauthenticated API documentation, including examples of calls to fetch route information and driver details. The accuracy of this data was confirmed by comparing it to the real-time status of the bus the researchers were riding.
Finally, the potential for APS UDP packet manipulation was described, explaining how decoded packets could be used to craft spoofed GPS locations or emergency signals. Although this wasn't a live "man-in-the-middle" demo on a moving bus for safety reasons, the detailed explanation of the packet structure and the ability to decode and re-encode them served as a strong proof of concept for this critical vulnerability. Collectively, these detailed accounts and visual aids provided a robust demonstration of the severe security flaws present in the smart bus system.
Defensive Implications
▶ Watch: Shocking Revelation: Officially Certified, Yet Insecure Devices (10:55)
The findings from "Smart Bus Smart Hacking: Free WiFi to Total Control" carry profound defensive implications for transportation companies, system vendors, and app developers involved in smart infrastructure. Addressing these vulnerabilities requires a multi-faceted approach, emphasizing security at every layer of design and implementation.
For Transportation Companies and System Vendors:
- Mandatory Secure Communications: All data transmission, especially for critical operational and safety systems like ADAS and APS, must use robust encryption protocols. This means abandoning unencrypted HTTP on port 80 in favor of HTTPS (TLS/SSL) for web interfaces and implementing secure, authenticated protocols for all machine-to-machine communications (e.g., encrypted MQTT, IPsec VPNs).
- Strong Authentication and Authorization: The pervasive use of default or weak credentials (e.g.,
admin/admin) is unacceptable. All devices and services must enforce strong, unique passwords, multi-factor authentication where feasible, and robust authorization mechanisms to ensure only legitimate users or systems can access specific functionalities. - Vendor Due Diligence and Cybersecurity Expertise: Transportation companies must prioritize vendors with a proven track record in cybersecurity. This includes evaluating their secure development lifecycle (SDLC), penetration testing practices, and commitment to addressing vulnerabilities promptly. "Official security certifications" should be critically reviewed and supplemented with independent, real-world penetration testing.
- Proper Network Segmentation and Isolation: The research highlighted a flat network where free public Wi-Fi provided direct access to critical internal systems. Implementing strict network segmentation is crucial. Guest Wi-Fi networks must be entirely isolated from operational technology (OT) networks using firewalls and access control lists (ACLs) to prevent unauthorized lateral movement. Different system components (e.g., ADAS, APS, DVR, M2M router) should reside in separate, isolated network segments with tightly controlled communication pathways.
- Regular Security Audits and Penetration Testing: Continuous security assessments, including external and internal penetration tests, are essential to identify and remediate vulnerabilities before they can be exploited by malicious actors. This should cover web applications, APIs, IoT devices, and network infrastructure.
- Patch Management: Systems running outdated software, like the BOA web server, are inherently vulnerable. A robust patch management program is necessary to ensure all software and firmware are kept up-to-date, addressing known CVEs and security flaws.
For Application Developers:
- Security by Design: Developers must integrate security considerations from the initial design phase of any system or application. This includes threat modeling to identify potential attack vectors and designing secure architectures that incorporate authentication, authorization, and encryption by default.
- Anti-Tampering Protection: Implement mechanisms to detect and prevent tampering with devices and software. This could include secure boot, integrity checks, and runtime protection against unauthorized code execution or modification.
- Secure API Development: All APIs, especially those exposing sensitive data or control functions, must be designed with strong authentication (e.g., OAuth, API keys), authorization, rate limiting, and input validation. Exposure of unauthenticated, comprehensive API documentation is a critical risk.
In essence, the talk serves as a urgent call for a holistic security overhaul in smart transportation. The convenience of interconnected systems must be balanced with rigorous security measures to protect against vulnerabilities that could compromise public safety, data privacy, and operational integrity.
Key Takeaways
- Free Wi-Fi as a Critical Attack Vector: The seemingly innocuous free Wi-Fi on public transportation can serve as a direct gateway to deeply embedded and critical operational systems, exposing an entire fleet to potential compromise.
- Pervasive Weak Authentication: The widespread use of default credentials (admin/admin) and easily bypassable login mechanisms (e.g., via known CVEs for old web servers like BOA) represents a fundamental and easily exploitable flaw across multiple devices.
- Lack of Encryption and Authentication in Critical Systems: Essential components like the ADAS web interface and APS UDP communications operate over unencrypted HTTP and without any authentication, leaving sensitive data (GPS, driver info, video) and control functions vulnerable to interception and manipulation.
- Poor Network Isolation: Critical operational networks are often not adequately segmented from public-facing or less secure networks, allowing attackers to pivot from a simple Wi-Fi connection to controlling core infrastructure.
- Inadequate Security Certifications: The research highlights that even devices that have passed "official security certification" can harbor severe, easily exploitable vulnerabilities, underscoring the need for more rigorous, real-world penetration testing.
- High Impact of Exploitation: Attackers can achieve total control, including monitoring all buses, accessing live video feeds, sending fake GPS data, triggering false emergency alerts, and altering system settings, posing significant risks to public safety and operational integrity.
About the Speaker(s)
Chiao-Lin Yu, also known as Stephen Meow, is a Senior Security Researcher specializing in red teaming at TMicro Taiwan. His expertise lies in identifying and exploiting vulnerabilities in complex systems, particularly within the realm of IoT security.
Kai Ching Wang, known by his alias Canniver, serves as a Deputy Manager in the Research and Development team at CHT Security. He focuses on advancing cybersecurity research and development initiatives.
Both speakers have a history of collaborating on numerous IoT security projects and have shared their findings at various international conferences in countries such as Japan and Taiwan, demonstrating their commitment to advancing security awareness and practices in critical technological domains.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent IoT attack chain research against real smart bus infrastructure — the target is interesting and the vulnerability chain is genuine — but the individual findings (BOA CVE, default creds, unencrypted HTTP, unauthenticated APIs) are so well-trodden that the talk's novelty is basically 'we applied 2015 IoT playbook to buses in Taiwan.' Still worth the slot at a regional con; at DEF CON it fills space without advancing the discipline.
Heather Calloway (CISO) — WEAK
Technically sound bug chain with real public safety implications, but the talk stops at discovery and never reaches the institutional or governance questions that would make it consequential for the people responsible for fixing it. The defensive section is a checklist, not a call to action.