Centre flags e-rickshaw BMS vulnerability, issues industry advisory

New Delhi: The Centre has issued an advisory to the automobile industry after E-rickshaw BMS vulnerability reports revealed that unauthorised users could remotely shut down moving electric three-wheelers through insecure Bluetooth-enabled battery systems.

The Indian Computer Emergency Response Team (CERT-In) said it received reports about the security flaw in the Battery Management System (BMS) used in some low-cost e-rickshaws.

According to CERT-In, the Bluetooth module in these BMS units often uses default credentials or no authentication. As a result, unauthorised users can connect through publicly available mobile applications and change battery settings or stop power discharge, causing the vehicle to shut down suddenly.

CERT-In identified the mobile applications capable of exploiting the vulnerability. It also informed the Ministry of Electronics and Information Technology to remove those applications from app stores.

E-rickshaw BMS vulnerability triggers safety measures

The Ministry of Heavy Industries has issued an advisory to SIAM, ACMA and authorised testing agencies to address the E-rickshaw BMS vulnerability and strengthen battery security.

The Ministry of Road Transport and Highways said cyber security regulations have not yet been notified specifically for e-rickshaws and e-carts. However, battery safety requirements remain covered under AIS 156, while electric powertrain safety must comply with AIS 038 Revision 2.

Meanwhile, the Ministry has published draft rules covering cyber security requirements for L, M and N category vehicles under AIS 189 and AIS 190. These draft regulations were notified on June 17, 2026.

The government also said every vehicle manufacturer or importer must obtain a Type Approval Certificate from a notified testing agency under Rule 126 of the Central Motor Vehicles Rules, 1989, before selling vehicles in India.