CERT-In reports Bluetooth BMS cybersecurity vulnerabilities in e-rickshaws; action sought to remove vulnerable apps
CERT-In flagged Bluetooth-based battery-management vulnerabilities in low-cost e-rickshaws and asked for vulnerable mobile apps to be removed from app stores.

- CERT-In reported that vulnerable e-rickshaw Battery Management Systems can be accessed through publicly available mobile applications and can lead to sudden vehicle shutdowns.
- The Ministry of Heavy Industries issued an advisory on Bluetooth Battery Management System vulnerabilities to automobile industry bodies and testing agencies.
- The Ministry of Electronics and Information Technology was asked to remove vulnerable mobile applications from application play stores.
What happened
CERT-In has reported safety concerns involving electric three-wheelers, or e-rickshaws, after finding that unauthorized users may be able to abruptly power off moving vehicles through a publicly available Battery Management System mobile application. The issue concerns the Bluetooth module inside the Battery Management System chip fitted in the battery module.
The Ministry of Heavy Industries has issued an advisory on Bluetooth Battery Management System vulnerabilities in e-rickshaws to the Society of Indian Automobile Manufacturers, the Automotive Component Manufacturers Association of India, industry bodies, and testing agencies.
UPSC can frame the topic as a cyber-physical security problem where weak authentication in a Battery Management System creates direct safety risks for passengers, operators, and urban transport systems. The issue also links technology governance, product testing, and regulatory coordination between the Ministry of Heavy Industries, CERT-In, and the Ministry of Electronics and Information Technology.
Related dispatches


