BusesTechnology

A vulnerability that can be controlled

In the autumn of 2025, Ruter AS drove two buses into a mountain hall to examine the buses’ electronics. The results could be interpreted in two ways. It has now emerged that the vulnerability they discovered is easily controllable, and that even modern buses are still relatively simple, with a low degree of integration between electronic components.

In November, the public transport company Ruter AS issued a press release—one that caused much of the world to view buses from China with skepticism. The press release gave the impression that buses from China could be remotely controlled.

After taking a closer look at what has emerged from this secret test and the subsequent report, the situation appears far less critical. The vulnerability found in modern buses can be easily controlled.

Today’s buses are still relatively simple technically, with a low degree of integration between components. The new buses are connected to the internet to enable software updates on board. The latter is the vulnerable element that can be controlled. In other words, one can simply disconnect the SIM card or take the system offline. In that way, the bus will not be able to receive updates or provide malicious actors with access.

Found in all modern vehicles, regardless of country of origin and brand

Such systems exist in almost all modern vehicles and are far more widespread among car manufacturers. Bus manufacturers are not as far along, but they are gradually catching up. Therefore, Ruter AS has already initiated measures to strengthen security and reduce risk.

Although Yutong was the bus manufacturer examined in this case, the vast majority of bus manufacturers—regardless of country of origin—have some form of wireless software update capability. That it happened to be a Chinese manufacturer in this instance is therefore more of a coincidence.

Ruter AS tells Aftenposten that the findings were better than feared and that they have already looked at various measures.

“That the technology was more advanced. Companies like ours, with long value chains, will always be exposed to risk. Therefore, it’s about reducing that risk to a manageable level,” says Cato Holter, Head of Emergency Preparedness at Ruter, to Aftenposten.

Lion-Cage

Ruter AS received assistance from Tor Indstøy and Arild Tjomsland to carry out this test on two buses. They deliberately chose buses of different ages to see how quickly bus technology is developing. The two are also known for the Lion-Cage project, in which they conduct similar investigations of passenger cars. At a recent conference, it was revealed that today’s modern passenger cars are far more advanced and “communicate” extensively with their manufacturer when the car is parked for the day, regardless of country of origin.

Lost bus orders due to a misleading press release

Yutong and other Chinese bus manufacturers have been inundated with calls from worried customers, and bus orders from several manufacturers are said to have been canceled following Ruter AS’s initial press release. Before Christmas, Yutong visited Norway and the United Kingdom with a delegation to explain how their buses are constructed. They also explained that all data is owned by the bus owner (the bus company itself) and that it is stored on a server in Frankfurt, Germany. Yutong itself cannot access this data; only the owner of the bus has access. They also comply with the EU’s strict data security requirements.

In many ways, this clarifying information has come to light far too late. The skepticism surrounding products from China was further reinforced by Ruter AS’s press release, and it may take a long time to correct this—if it can be corrected at all.