Skip to main content

Security expert buys a Mitsubishi Outlander Hybrid to confirm Wi-Fi vulnerability

2016 Mitsubishi Outlander Sport
Image used with permission by copyright holder
Connected car security concerns have become and will continue to be “a thing.” The latest issue, and one that deserves immediate notice, is about the Mitsubishi Outlander Hybrid SUV. A British security expert discovered a vulnerability in the Outlander’s onboard Wi-Fi almost by accident while waiting to pick up his kids after school, according to BBC News. As a result of his report and a demo to Mitsubishi, the company has advised owners to disable Wi-Fi in their vehicles until it figures out a fix.

Ken Munro was in his car when he noticed a Wi-Fi access point from a friend’s nearby Outlander. When Munro asked about it his friend explained how the system worked and what he could do with it from his cell phone. Munro tried the app and quickly found a troublesome vulnerability. So he got out of the app immediately.

What Munro did next isn’t what you would likely do, but he promptly bought an Outlander and took it to his company to check out the problem. What may seem like an overly cautious (not to mention expensive) reaction to a Wi-Fi weakness resulted in the manufacturer acknowledging the potential problem and recommending owners stop using Wi-Fi by de-registering their access points.

The issue Munro found was that remote commands sent to the Outlander go directly to the car’s access point, not through a third-party web server, which is the practice with most carmakers. Second, the access point name was distinct and could easily end up on websites that collect and display nearby access points. Munro and his colleagues used unnamed but “well-known techniques that let the researchers interpose themselves between car and owner and watch data as it flowed between the two.”

With access to the car’s system, anyone could flash the lights, drain the battery, and change other settings. The most disturbing finding, however, was the ability to disable the car’s alarm system. This could give thieves a chance to break in to steal the car’s contents, components, and possibly even the car itself.

Related: Driverless cars could be used for assassination, says Attorney General

“This hacking,” Mitsubishi acknowledged in a statement released to BBC News, “is a first for us as no other has been reported anywhere else in the world.” Mitsubishi recommended owners cancel the access point VIN registration via the smartphone app or with the car’s remote.

If you own a Mitsubishi Outlander Hybrid, there are three steps to be followed in order to delete the VIN registration. First, turn on the hazard lights. Second, within 30 seconds, and with the doors closed, press the Lock/Unlock button on the remote 10 times. That will put you in registration delete mode. Wait for the beeping to stop — if the system is registered there will be one beep with an additional beep for each device registered with the access point, so just wait. Then, within 5 minutes, and again with the doors closed and using the car remote, press the Lock/Unlock button 20 times. Those steps will de-register your car’s Wi-Fi system. Then wait until you get word that it’s OK to register it again after Mitsubishi figures out a solution.

This hasn’t been a great year for Mitsubishi with its admission of fuel economy test cheating and resulting slower sales. Hopefully, the company can resolve the Wi-Fi security issue quickly.

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
Mercedes-Benz G580 first drive: old-school off-roader goes electric
2025 Mercedes-Benz G580 from three quarter view.

American car buyers mostly know Mercedes-Benz as a luxury brand. But for decades, the automaker has also produced the tough, rugged G-Class (also known as the Geländewagen or G-Wagen), an SUV not afraid to get its leather upholstery muddy. And now, this iconic Mercedes is going electric.

The 2025 Mercedes-Benz G580 with EQ Technology — the final name of the SUV previously known as the EQG — isn’t the first electric off-roader. The Rivian R1S and R1T and GMC Hummer EV have proven that electric powertrains and off-roading are a great combination. But the electric G-Wagen is different because it’s based on an internal-combustion model — and a very traditional one at that.

Read more
Honda believes hydrogen semi trucks will make the case for fuel cells
Honda hydrogen fuel-cell semi truck.

Honda remains committed to hydrogen fuel-cell vehicles, but the market for those vehicles remains limited. So Honda is looking at other uses for fuel cells -- including commercial trucks.

To show how that could work, Honda converted a semi truck to fuel-cell power, replacing its diesel engine with three fuel-cell modules. Together, the three modules produce a combined 321 horsepower, and can propel the truck to a top speed of 70 mph. There's enough onboard hydrogen storage capacity for a 400-mile range with a full load, Honda claims.

Read more
Mercedes-Benz G580 vs Rivian R2: Is the much cheaper Rivian actually better?
2025 Mercedes-Benz G580 from three quarter view.

Mercedes-Benz has finally taken the wraps off of the new "Mercedes-Benz G580 with EQ Technology." Yeah, it's a mouthful, but it's basically a new electric G-Wagon. It looks a lot like the G-Wagon you know and love, but with an electric powertrain and a battery. It's not the only electric SUV out there, however, and there are some great ones -- like the Rivian R2.

Both the Mercedes G580 and the Rivian R2 have a lot going for them, but they also approach the electric SUV slightly differently. Is one better than the other? I put the two head-to-head to find out.
Design
The approach that the two vehicles take to design is quite different -- and you might like one better than the other.

Read more