Category: IT|Jan 23, 2025 | Author: Admin

Tesla EV charger hacked twice on second day of Pwn2Own Tokyo

Share on

​Security researchers hacked Tesla's Wall Connector electric vehicle charger twice on the second day of the Pwn2Own Automotive 2025 hacking contest.

Tesla EV charger hacked twice on second day of Pwn2Own Tokyo

Tesla EV charger hacked twice on the second day of Pwn2Own Tokyo


​Security researchers hacked Tesla's Wall Connector electric vehicle charger twice on the second day of the Pwn2Own Automotive 2025 hacking contest.

 

They also exploited 23 more zero-day vulnerabilities in WOLFBOX, ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, and EMPORIA EV chargers, as well as in the Alpine iLX-507, Kenwood DMX958XR, Sony XAV-AX8500 In-Vehicle Infotainment (IVI) systems.

 

PHP Hooligans were the first to crash the Tesla Wall Connector after using a Numeric Range Comparison Without a Minimum Check zero-day bug to take over the device. They were followed by Synacktiv, who also hacked Tesla's EV charger via the Charging Connector, an approach that's never been demonstrated publicly before.

 

Today, two bug collisions occurred during Tesla Wall Connector hacking attempts: one by team PCAutomotive and the other by the Summoning Team's Sina Kheirkhah, who used an exploit chain of two already-known bugs.

 

According to the Pwn2Own Tokyo 2025 contest rules, all devices targeted during the competition must have all security updates installed and run the latest operating system versions.

 

Trend Micro's Zero Day Initiative awarded $335,500 in cash rewards during the second day for 23 zero-day vulnerabilities. Sina Kheirkhah is currently in the lead for Master of Pwn.

 

​On the first day of Pwn2Own Automotive, security researchers exploited 16 unique zero-day vulnerabilities and collected $382,750 in cash awards. After the competition ends, vendors will have 90 days to develop and release security fixes before ZDI publicly discloses the zero-day bugs.

 

​The Pwn2Own Automotive 2025 hacking contest will focus on automotive technologies from January 22 to January 24 during the Automotive World conference in Tokyo, Japan.

 

Hackers will target car operating systems (i.e., Automotive Grade Linux, Android Automotive OS, and BlackBerry QNX), electric vehicle (EV) chargers, and in-vehicle infotainment (IVI) systems.

 

Even though Tesla also provided a Model 3/Y (Ryzen-based) equivalent benchtop unit, no security researcher had registered an attempt against the company's wall connector before the competition's schedule was published. The schedule for the second day and the results for each challenge can also be found here.

 

One year ago, during the first edition of Pwn2Own Automotive in Tokyo, security researchers were awarded $1,323,750 for hacking a Tesla twice and exploiting 49 zero-day bugs in multiple electric car systems.

Sponsored Ads:

Comments:


Outlook-14-03-25.png

Microsoft says button to restore classic Outlook is broken

Category: Microsoft|Mar 14, 2025 | Author: Admin
GitLab-13-03-25.png

GitLab patches critical authentication bypass vulnerabilities

Category: IT|Mar 13, 2025 | Author: Admin
Firefox-12-03-25.png

Mozilla warns users to update Firefox before certificate expires

Category: Microsoft|Mar 12, 2025 | Author: Admin
Windows-headpic-11-03-25.png

Microsoft replacing Remote Desktop app with Windows App in May

Category: Microsoft|Mar 11, 2025 | Author: Admin
swiss-flag-10-03-25.png

Swiss critical sector faces new 24-hour cyberattack reporting rule

Category: IT|Mar 10, 2025 | Author: Admin
sound-waves-09-03-25.png

New Chirp tool uses audio tones to transfer data between devices

Category: IT|Mar 9, 2025 | Author: Admin
esp32-08-03-25.png

Undocumented "backdoor" found in Bluetooth chip used by a billion Devices

Category: IT|Mar 8, 2025 | Author: Admin
webcam-07-03-25.png

Ransomware gang encrypted network from a webcam to bypass EDR

Category: IT|Mar 7, 2025 | Author: Admin
Microsoft-365-06-03-25.png

Microsoft 365 apps will prompt users to back up files in OneDrive

Category: Microsoft|Mar 6, 2025 | Author: Admin
YouTube-05-03-25.png

YouTube warns of AI-generated video of its CEO used in phishing attacks

Category: Google|Mar 5, 2025 | Author: Admin
Microsoft_365-04-03-25.png

New Microsoft 365 outage impacts Teams, causes call failures

Category: Microsoft|Mar 4, 2025 | Author: Admin
UK-ICO-03-03-25.png

UK watchdog probes TikTok and Reddit over child privacy concerns

Category: IT|Mar 3, 2025 | Author: Admin
artificial-intelligence-eyes-02-03-25.png

Nearly 12,000 API keys and passwords found in AI training dataset

Category: IT|Mar 2, 2025 | Author: Admin
Android-01-03-25.png

Serbian police used Cellebrite zero-day hack to unlock Android phones

Category: Google|Mar 1, 2025 | Author: Admin
Skype-28-02-25.png

Microsoft confirms it's killing off Skype in May, after 14 years

Category: IT|Feb 28, 2025 | Author: Admin
more