RE: https://sfba.social/@ryanboswell/116955954613253992
“An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.”
Just amazing.
I likely comes as no surprise that at least some EV charging infrastructure has been rolled out with laughably bad security.
The fact that someone could probably cause significant damage to the local power grid or plant malware for future vehicles connected with very little real effort is wild, especially since many chargers are in only minimally protected public spaces.
It’s like being able to stick in a specially formatted debit card and suddenly have full access to a bank’s entire internal system.
https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers