HackerOne · VDP

Daimler Truck Vulnerability Disclosure Program

Complete guide to Daimler Truck's vulnerability disclosure program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Daimler Truck runs a vulnerability disclosure program on HackerOne. The program has 272 in-scope assets and is managed by HackerOne's triage team.

272
In-Scope Assets
2h
Avg Response
93%
Efficiency
235d
Avg Resolve

In-Scope Assets

AssetTypeMax SeverityEligible
*.bharatbenz.comOTHERCriticalNo Bounty
*.daimlertruck.comURLCriticalNo Bounty
*.freightliner.comOTHERCriticalNo Bounty
*.mercedes-benz-trucks.comURLCriticalNo Bounty
*.setra.deURLCriticalNo Bounty
*.westernstar.comURLCriticalNo Bounty
*detroitconnect.comOTHERCriticalNo Bounty
*exceleratorparts.comWILDCARDCriticalNo Bounty
*fleetboard.comURLCriticalNo Bounty
*fleetboard.deURLCriticalNo Bounty
*omniplus.comURLCriticalNo Bounty
033634aa-bd31-4486-abab-8a66a93bbf2c.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
04fabe21-8c9d-46a6-80d6-aaab87ad79df.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
060.syncro-int.daimlertruck.comURLCriticalNo Bounty
174d7a96-079c-4168-8493-bcb044fd5e89.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
1755a284-ff9a-4d50-b9b9-50c8748e533c.ops.reverse.svc.fleetboard.comURLCriticalNo Bounty
227242d5-a18b-427f-967b-52aece59fc95.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
22f3edd8-87d1-4a29-a79d-7f5951ca28a2.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
33cf3452-c7f8-4507-8691-8ae16b52b738.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
3c3ff562-1a06-40e2-9c07-24458aeb5867.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
3dprintdata.daimlertruck.comURLCriticalNo Bounty
3dviewer.daimlertruck.comURLCriticalNo Bounty
649276e0-2937-4e1a-be9d-6ddbeab592f3.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
66f36d7b-4fdd-4061-a8ee-1e618ce28ac7.ops.reverse.svc.fleetboard.comURLCriticalNo Bounty
6a3b1cdb-d170-4e8c-bfd8-a89e14dbff8b.ops.reverse.svc.fleetboard.comURLCriticalNo Bounty
6ad07e2b-5c6c-4378-83ca-bc2828e76f63.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
72071376-4421-4c12-ad40-7b7cabe93380.ops.reverse.svc.fleetboard.comURLCriticalNo Bounty
7c905fb0-ac0e-4c32-8191-419d531bf79a.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
All Apps published by Daimler Truck AGOTHERCriticalNo Bounty
VehiclesOTHERCriticalNo Bounty
aa34404a-8a41-4186-ad0c-650cd3d36a48.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
aa678174-5fc1-48eb-8446-567df8685032.prod.reverse.svc.fleetboard.comURLCriticalNo Bounty
academy.fleetboard.comURLCriticalNo Bounty
access.mbs-navigator.comURLCriticalNo Bounty
access.platon.daimlertruck.comURLCriticalNo Bounty
accon.tsac-staging.daimlertruck.comURLCriticalNo Bounty
accon.tsac.daimlertruck.comURLCriticalNo Bounty
accord-produit-test.daimlertruck.comURLCriticalNo Bounty
accord-produit.daimlertruck.comURLCriticalNo Bounty
acmeautotest.treasure.daimlertruck.comURLCriticalNo Bounty
acsmgt.t3-int.daimlertruck.comURLCriticalNo Bounty
acsmgt.t3.daimlertruck.comURLCriticalNo Bounty
admin-cal-sil-dev.tsac-staging.daimlertruck.comURLCriticalNo Bounty
admin-cal-sil-int.tsac-staging.daimlertruck.comURLCriticalNo Bounty
admin-cal-sil-preprod.tsac-staging.daimlertruck.comURLCriticalNo Bounty
admin-cal-sil.tsac.daimlertruck.comURLCriticalNo Bounty
admin-card-sil-dev.tsac-staging.daimlertruck.comURLCriticalNo Bounty
admin-card-sil-int.tsac-staging.daimlertruck.comURLCriticalNo Bounty
admin-card-sil-preprod.tsac-staging.daimlertruck.comURLCriticalNo Bounty
admin-card-sil.tsac.daimlertruck.comURLCriticalNo Bounty

Showing 50 of 272 in-scope assets. View all on HackerOne.

Out-of-Scope Assets

  • *.daimler.com
  • *.fuso.com
  • *.mitsubishi-fuso.com
  • *.thomasbuildbuses.com
  • *evobus.com

Tips for Hacking Daimler Truck

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Daimler Truck?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Daimler Truck pay bounties?

No, Daimler Truck runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.

What types of vulnerabilities does Daimler Truck accept?

Daimler Truck accepts reports for vulnerabilities found in their 272 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.