Desk live·
ForensicPost
Cloud/API/File 23-0608

A Honda Password Reset Endpoint Accepted Any Email Address Without a Token

A researcher found that one of Honda’s dealer platforms would reset the password on any account given only a valid email address. Honda fixed it, found no evidence anyone else had used it, and paid nothing — there was no bug bounty to pay from.

Constructed geometry · not a chart of case data
TargetHonda dealer platform
ActorUnattributed
D. Kennedy9 min readConfidence: high2 sources reviewed

Security researcher Eaton Zveare published findings on flaws in a Honda e-commerce platform serving power equipment, marine and lawn and garden dealers. The password reset API processed requests without a token or the previous password, requiring only a valid email address.

Broken access controls compounded it: an account obtained that way could reach data across the platform. The researcher reported reachable records covering thousands of dealer accounts and sites and tens of thousands of customer orders. Honda was notified on 16 March 2023 and confirmed the issues fixed by 3 April.

This File Is Here Because Nothing Happened

Honda reported finding no evidence of malicious exploitation. There is no victim count, no notification and no incident — and the corpus carries it deliberately.

A database assembled only from incidents that produced harm systematically overstates how often a flaw is found by an attacker first. This one was found by somebody who reported it, and the difference between this file and 23-0119 is not the severity of the flaw but who happened to reach it.

Reset Is An Authentication Path

Password reset is where a great deal of authentication effort quietly goes to die. It exists to let a user in without the credential, which makes it, by construction, an alternative route to the thing every other control protects.

The corpus records help desks as the human version of this at 23-0911 and 25-0806. Reset is the machine version, and it is subject to less scrutiny because nobody thinks of it as a login.

There Was Nothing To Pay Him From

Reporting notes Honda had no bug bounty programme and the researcher received no reward. That is not misconduct and this file does not treat it as such.

It is worth recording because the corpus argues at 26-0323 and 26-0321 that coordinated disclosure assumes a maintainer able and motivated to act. Where the finder’s only incentive is professional goodwill, the supply of finders is a volunteer effort holding up a commercial system.

How we reported this

Built on contemporaneous reporting of the researcher’s published findings. The nature of the password reset flaw, the access control failures, the categories and counts of reachable records, the 16 March report date and the 3 April fix confirmation are from that reporting of the researcher’s disclosure and Honda’s response. Honda’s statement that it found no evidence of malicious exploitation is Honda’s. This desk has not independently tested the platform and no exploitation is asserted. No individual customer or dealer is identified. Graded high on the disclosure and the vendor response; there is no incident to grade. Corrections: corrections@forensicpost.com.

Sources
  1. Honda API flaws exposed customer data, dealer panels, internal docsBleepingComputer
  2. Password Reset Hack Exposed in Honda’s E-Commerce Platform, Dealers Data at RiskThe Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary