Wayfare Mobility
Bug bountyWayfare Mobility Systems GmbH
Connected-vehicle and fleet telematics. Bench hardware only, and never a vehicle that is in service.
- Accepting reports
- $200 – $15,000
- 9 assets in scope
- Launched Nov 2020
- wayfare.example
Read the policy · first response 3 business days
Response times
- first response
- 2 business days
- triage
- 6 days
- reward
- 23 days
- resolution
- 104 days
Program to date
- Resolved
- 1,186
- Total paid
- $1.06M
- Thanked
- 284
- Average
- $2,874
Rewards by severity
Final amounts depend on demonstrated impact, report quality and asset criticality.
| Severity | CVSS | Reward | Typical findings |
|---|---|---|---|
| Critical | 9.0 – 10.0 | $7,000 – $15,000 | Code execution on the telematics unit reached over the cellular interface, a forged update manifest accepted by a production vehicle, any path from an external radio into the vehicle bus gateway. |
| High | 7.0 – 8.9 | $2,500 – $6,500 | Fleet-wide trip history readable across operator boundaries, authentication bypass on the remote-command endpoint, secure boot defeat on the head unit that survives a power cycle. |
| Medium | 4.0 – 6.9 | $600 – $2,200 | Pairing a driver phone to a cab that is not yours, privilege escalation inside the head unit sandbox, a diagnostics session key derived from values printed on the housing. |
| Low | 0.1 – 3.9 | $200 – $550 | Service ports reachable on a bench unit in its shipped configuration, identifiers in logs that resolve to a vehicle but not to a driver, unsigned non-executable assets inside a firmware bundle. |
In scope
9 assets listed, 8 eligible for a reward. Anything not on this list is out of scope.
| Asset | Type | Max severity | Reward | Notes |
|---|---|---|---|---|
| Wayfare TCU-6 telematics control unit | Hardware | Critical | Eligible | Bench units on a workbench harness. A unit fitted to a vehicle is out of scope even when the vehicle is yours. |
| Wayfare HU-4 infotainment head unit | Hardware | Critical | Eligible | Bench or developer unit. Secure boot, sideloading and escapes out of the driver-facing sandbox are the priority. |
| wayfare-os 4.x firmware bundles | Executable | Critical | Eligible | Signed images published at ota.wayfare.example. Signature checking and rollback protection first, everything else second. |
| https://api.wayfare.example/fleet/v3 | API | Critical | Eligible | Fleet management and remote commands. Rate limited to 20 rps per bench account; ask before anything heavier and we will raise it for a window. |
| ota.wayfare.example | Network | Critical | Eligible | Update distribution: manifest service, transport, and the campaign scheduler behind it. Testable without a paired unit since April 2023. |
| Wayfare Drive (Android) | Android | High | Eligible | Driver app. Pairing, command signing and credential storage. Build 9.x only; 8.x no longer receives fixes. |
| Wayfare Drive (iOS) | iOS | High | Eligible | Same surface as the Android build. Keychain handling and pinning bypasses are both wanted. |
| https://api.wayfare.example/fleet/v2 | API | Medium | Eligible | Frozen at the v3 cutover; three operators stay on it until March 2027. Capped at Medium, and only authorisation defects get backported. |
| depot.wayfare.example | URL | Medium | No reward | Depot provisioning console, built and hosted for us by an integrator. We triage and credit findings here, and we cannot pay for them. |
Out of scope
| Asset | Why |
|---|---|
| Any vehicle in motion, on a public road, or with a person aboard | Safety. No finding is worth a collision, and testing of this kind ends participation the day we learn of it. |
| Vehicles belonging to someone else, including rentals, press cars and operator fleets | We cannot authorise testing of property we do not own. Neither can the operator, on our behalf. |
| Bus fuzzing against a control unit fitted to an assembled vehicle | Bench harnesses only. A fuzzed unit can end up in a state that needs a dealer tool, and on a drivable vehicle that is a safety matter. |
| wayfare-os 3.x and the TCU-4 hardware generation | Left scope on 31 August 2025 when the last operator finished migrating. We accept no further reports against either. |
| Cellular modem firmware, the GNSS module and licensed map data | Supplier silicon and supplier data, each covered by that vendor's own disclosure process. We will introduce you. |
| partners.wayfare.example | Dealer and workshop portal run by a regional franchise group on infrastructure we have no access to. |
| Relay attacks on third-party key fobs, lock picking, and vehicle theft technique generally | Outside the electronic surface this programme covers, and handled by our physical security team. |
Findings that will be closed as informative
- Anything reproduced on a moving vehicle, on a public road, or on a vehicle carrying passengers.
- Findings that require you to disassemble a vehicle you do not own.
- Serial console or JTAG access on a bench unit with the housing already off, unless it leads somewhere further.
- Theoretical bus message injection with no traced path from an external interface.
- Availability testing against the cellular backend, the manifest service, or vehicle connectivity.
- Reports built from decompiled app strings with no working reproduction.
- Known weaknesses of legacy diagnostic standards, which we document and do not claim to have fixed.
- Battery, thermal and mechanical safety claims, which belong to product safety and not to this inbox.
- Aftermarket dongles and third-party accessories plugged into the diagnostic port.
Program policy
Program overview
Wayfare builds the connected layer of a commercial vehicle: the telematics unit that talks to our backend, the head unit the driver touches, the phone app that unlocks and preconditions a cab, and the update channel that keeps all of it current. Around 412,000 vehicles across 23 fleet operators carry our hardware, most of them vans and light trucks in daily service.
Our own product security incident response team runs this programme. Nobody sits between you and the engineer who owns the firmware. That is a choice with a price: a firmware fix is validated on a hardware-in-the-loop rig before it is staged into an update campaign, and a campaign can take six weeks to reach a fleet that parks indoors only at weekends. The resolution figure above is the real one.
Since June 2022 we have posted bench hardware to researchers rather than leave them hunting the second-hand market. It did more for report quality than any rewrite of this page.
Testing rules and expectations
One rule outranks every other rule here, and it is not negotiable.
Never test against a vehicle that is moving, on a public road, or with a person aboard. Not a slow roll across a yard, not with a colleague at the wheel and a hand on the brake. Where a finding can only be reached on a vehicle in service, write up the theory and we will reproduce it ourselves on the proving ground with a safety driver and a closed surface. You are paid as though you had reached it yourself; that has happened eleven times.
The rest follows from it.
- Hardware work happens on a bench harness. Buy a unit, take one out of a vehicle you own outright, or ask for a loaner.
- No CAN, LIN or automotive Ethernet fuzzing against a unit fitted to an assembled vehicle. Fuzzing leaves a control unit in a state that needs a dealer tool, and on something that still drives that is a safety problem rather than an inconvenience.
- Backend work goes through a bench account bound to your own units; ask and we will provision one with synthetic fleet data inside a day. Do not enumerate vehicle identifiers that are not yours.
- No availability testing against the cellular backend. In several markets, a vehicle that loses connectivity loses its emergency call feature with it.
- No social engineering of drivers, dispatchers, depot staff, dealers or our own people, and nothing physical at any of our sites.
- Trip histories are personal data. If you reach one that is not yours, keep a single record as proof, stop, and delete the rest.
Proving write access
If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.
- One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
- Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
- Revert within sixty seconds, in the same run, without being asked.
- Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
- If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.
Every request must carry headers that let us separate your traffic from a real attack in our logs:
X-Bug-Bounty: wayfare-mobility
X-Research-Account: <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id: <unique per request>
User-Agent: sentinel-research/<handle> (+<this page>)
scripts/proof_of_write.py performs exactly this sequence, refuses any host
outside the scope above, refuses a diff longer than two characters, always
attempts the revert, and writes a timestamped evidence file. Run it without
--execute first, then attach the evidence to your report.
Safe harbour
Stay inside the rules above and your work is authorised. We will not bring a legal action, will not support anyone else's, and will confirm your authorisation in writing to an employer, an operator or a regulator who asks. We have written eight such letters since 2021.
The protection covers electronic research on equipment you own or we loaned you, and on the backend assets in scope. It does not reach a vehicle owned by somebody else, an operator's depot, our suppliers' systems, or anything fitted to a vehicle in service. It ends if driver location data is kept past the point of proof, and it ends if a finding is shown publicly on a road.
Should testing ever put a person in physical danger, we will handle it as a safety incident first and a security report second, and cooperate with any authority that asks.
Reward decisions
Severity starts from CVSS v3.1, then is adjusted for reachability, which in a vehicle counts for more than the vector string suggests. A defect an attacker reaches over cellular from another country pays bands above the same defect that needs an unlocked cab and ten minutes with a laptop.
Physical-access findings cap at High unless they leave a persistent foothold triggerable remotely. Anything crossing from an external radio into the bus gateway is Critical, without argument: that boundary is why the architecture has the shape it has.
Duplicates go to the first reproducible report, and since March 2024 the window runs from triage rather than from submission. Chained findings pay once at the severity of the outcome, plus a 15 percent analysis bonus.
The 2023 forged-manifest report is the one we measure others against. It paid the top of the Critical band with the bonus and went further than money: we opened a voluntary field safety campaign with our type-approval authority and re-flashed 6,400 vehicles.
Disclosure policy
We ask for 180 days. The reason is the campaign calendar rather than reluctance. Where a fix lands sooner, the clock stops when the campaign closes for the affected operators, and we send you the date.
After that, publish. Redact vehicle identification numbers, operator names, subscriber identifiers, keys, and anything that resolves to a named driver. To present before day 180, tell us early; we have never refused, and three times one of our engineers has stood on stage beside the researcher.
Report quality
Reports that move fastest through our rig queue carry all of this:
- Hardware revision, firmware build string and app version, copied from the unit rather than remembered.
- Whether the unit was bought, loaned by us, or pulled from a vehicle you own.
- A photograph or sketch of the bench topology wherever a harness, probe or glitcher is involved.
- Steps a firmware engineer can follow on an identical rig, with nothing left implicit.
- The external entry point stated outright: cellular, Wi-Fi, Bluetooth, USB, diagnostic port or local console.
- Raw captures rather than screenshots: a pcap, a bus log or a serial transcript.
Hall of fame
Researchers who have reported valid issues to this program.
| # | Researcher | Country | Reports | Points |
|---|---|---|---|---|
| 1 | torquevector | Germany | 41 | 5,880 |
| 2 | obd_wren | Sweden | 37 | 5,210 |
| 3 | uds_session | South Korea | 26 | 4,745 |
| 4 | hu_teardown | Japan | 33 | 4,180 |
| 5 | manifest_moth | United States | 29 | 3,690 |
| 6 | canbus_kat | Finland | 31 | 3,215 |
| 7 | glitch_harness | Poland | 17 | 2,860 |
| 8 | solderfume | Czechia | 24 | 2,405 |
| 9 | gnss_drift | Israel | 19 | 2,030 |
| 10 | fleetkeyrot | Brazil | 22 | 1,655 |
| 11 | lin_lisa | Netherlands | 14 | 1,290 |
| 12 | bench_rat | Argentina | 12 | 980 |
| 13 | immo_bypass | South Africa | 9 | 715 |
| 14 | vin_tumbler | India | 6 | 430 |
Program updates
-
Loaner waiting list cleared
Everyone who applied for a TCU-6 or HU-4 bench kit before August now has one in the post. The queue had run to five months after the Season of the Van talk; it is back to three weeks.
-
Head unit build 11 opens the sandbox boundary to testing
The new application sandbox on HU-4 build 11 is the surface we most want looked at. Escapes out of it are Critical for as long as the build is in staged rollout.
-
Medium band raised to 2,200 USD
Pairing and session-key findings were landing at the top of the old band far too often, which meant the band was wrong rather than the reports.
-
Safety rule restated after a parked-vehicle test
A researcher sent a remote climate command to a parked vehicle with a person inside it. Nobody was hurt. The rule now has no exception and we will end participation over it.
-
wayfare-os 3.x and the TCU-4 left scope
The last operator finished migrating to 4.x on 29 August, and the older branch stopped receiving fixes two days later. Reports against it are closed with a pointer to this entry.
-
Report quality checklist rewritten around bench topology
Half of the reproduction delays last year came from not knowing how a rig was wired. A photograph or a sketch of the harness is now the first thing we ask for.
-
Field safety campaign closed for the manifest finding
The voluntary campaign opened with our type-approval authority after the 2023 forged-manifest report finished re-flashing 6,400 vehicles. The researcher was credited in the filing with their consent.
-
Duplicate window now measured from triage
A Friday evening report lost a duplicate call to one sent on the Monday and read first. The window starts when a report is triaged, and we reopened the two cases affected.
-
First remote-reachable Critical paid at 15,000 USD
A forged update manifest was accepted by a bench unit and then by a vehicle on our proving ground. It is still the report we hold up as the example of what the top band is for.
-
Update manifest service moved into scope
The manifest endpoint can now be tested directly rather than only through a paired unit. Forged manifests pay at the Critical band whether or not a unit accepts them.
-
Bench hardware loan programme opened
Researchers with two accepted reports can ask for a TCU or head unit development kit. The units are theirs to keep and we have never asked for one back.
-
Programme opened to the public
Our product security incident response team took over an invitation-only pilot that had run through the previous spring. Eleven operators carried our hardware then; twenty-three do now.