Skip to main content

Security expert buys a Mitsubishi Outlander Hybrid to confirm Wi-Fi vulnerability

2016 Mitsubishi Outlander Sport
Image used with permission by copyright holder
Connected car security concerns have become and will continue to be “a thing.” The latest issue, and one that deserves immediate notice, is about the Mitsubishi Outlander Hybrid SUV. A British security expert discovered a vulnerability in the Outlander’s onboard Wi-Fi almost by accident while waiting to pick up his kids after school, according to BBC News. As a result of his report and a demo to Mitsubishi, the company has advised owners to disable Wi-Fi in their vehicles until it figures out a fix.

Ken Munro was in his car when he noticed a Wi-Fi access point from a friend’s nearby Outlander. When Munro asked about it his friend explained how the system worked and what he could do with it from his cell phone. Munro tried the app and quickly found a troublesome vulnerability. So he got out of the app immediately.

Recommended Videos

What Munro did next isn’t what you would likely do, but he promptly bought an Outlander and took it to his company to check out the problem. What may seem like an overly cautious (not to mention expensive) reaction to a Wi-Fi weakness resulted in the manufacturer acknowledging the potential problem and recommending owners stop using Wi-Fi by de-registering their access points.

Please enable Javascript to view this content

The issue Munro found was that remote commands sent to the Outlander go directly to the car’s access point, not through a third-party web server, which is the practice with most carmakers. Second, the access point name was distinct and could easily end up on websites that collect and display nearby access points. Munro and his colleagues used unnamed but “well-known techniques that let the researchers interpose themselves between car and owner and watch data as it flowed between the two.”

With access to the car’s system, anyone could flash the lights, drain the battery, and change other settings. The most disturbing finding, however, was the ability to disable the car’s alarm system. This could give thieves a chance to break in to steal the car’s contents, components, and possibly even the car itself.

Related: Driverless cars could be used for assassination, says Attorney General

“This hacking,” Mitsubishi acknowledged in a statement released to BBC News, “is a first for us as no other has been reported anywhere else in the world.” Mitsubishi recommended owners cancel the access point VIN registration via the smartphone app or with the car’s remote.

If you own a Mitsubishi Outlander Hybrid, there are three steps to be followed in order to delete the VIN registration. First, turn on the hazard lights. Second, within 30 seconds, and with the doors closed, press the Lock/Unlock button on the remote 10 times. That will put you in registration delete mode. Wait for the beeping to stop — if the system is registered there will be one beep with an additional beep for each device registered with the access point, so just wait. Then, within 5 minutes, and again with the doors closed and using the car remote, press the Lock/Unlock button 20 times. Those steps will de-register your car’s Wi-Fi system. Then wait until you get word that it’s OK to register it again after Mitsubishi figures out a solution.

This hasn’t been a great year for Mitsubishi with its admission of fuel economy test cheating and resulting slower sales. Hopefully, the company can resolve the Wi-Fi security issue quickly.

Bruce Brown
Bruce Brown Contributing Editor   As a Contributing Editor to the Auto teams at Digital Trends and TheManual.com, Bruce…
Mini’s infotainment system is very charming, but still needs work
Main screen of the Mini infotainment system

When you think Mini, you probably don’t think of infotainment. Personally, I think of the British flag taillights, the distinct exterior, and the surprising room on the inside. But after driving the Mini John Cooper Works Countryman over the past week, infotainment might well be something I think of more often when it comes to Mini. It’s charming.

It also, however, suffers from all the traps that other legacy automakers fall into when it comes to software design. Mini has something on its hands here — but it still needs some work.
Bringing the charm
The first thing that stood out to me about the system when I got in the car was how fun it was. That all starts with the display. It’s round! No, it’s not curved — the screen is a big, round display sits in at 9.4 inches, and I found it plenty large enough for day-to-day use.

Read more
Plug-in hybrids are becoming more popular. Why? And will it continue?
Kia Niro EV Charging Port

There's a lot of talk about the idea that the growth in electric car sales has kind of slowed a little. It's not all that surprising -- EVs are still expensive, early adopters all have one by now, and they're still new enough to where there aren't too many ultra-affordable used EVs available. But plenty of people still want a greener vehicle, and that has given rise to an explosion in hybrid vehicle sales.

That's especially true of plug-in hybrid vehicles, which can be charged like an EV and driven in all-electric mode for short distances, and have a gas engine as a backup for longer distances or to be used in combination with electric mode for more efficient driving.

Read more
EV drivers are not going back to gas cars, global survey says
ev drivers are not going back to gas cars global survey says screenshot

Nearly all current owners of electric vehicles (EVs) are either satisfied or very satisfied with the experience, and 92% of them plan to buy another EV, according to a survey by the Global EV Drivers Alliance.

The survey of 23,000 EV drivers worldwide found that only 1% would return to a petrol or diesel car, while 4% would opt for a plug-in hybrid (PHEV) if they had to replace their car.

Read more