DEF CON 33 - One Modem to Brick Them All -Vulns in EV Charging Comms - Jan Berens, Marcell Szakaly

DEF CON 33 - One Modem to Brick Them All -Vulns in EV Charging Comms - Jan Berens, Marcell Szakaly

Source: YouTube · DEFCONConference · published Sep 8, 2025 · 43:20

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The researchers reveal critical security vulnerabilities in EV charger communication modems, showing that attackers can manipulate charging sessions and potentially disrupt infrastructure 0:02.

Key Takeaways:
• Over half of EV chargers tested use firmware more than 10 years old with no security patches applied 5:56
• The "PIB buster" attack allows rogue EVs or chargers to override each other's configurations through the charging cable 8:24
• Testing of 41 chargers in California revealed all lacked write protection, making them vulnerable to attacks 18:20
• Even when security features are enabled, attackers can bypass them by resetting the device remotely 22:10
• Ground-based attacks allow disruption of charging without physical connection to cables 28:55
• Researchers demonstrated running custom firmware on these chips, including a Doom port, highlighting their complete compromise 37:00

The researchers conclude that PLC (Power Line Communication) technology in EV charging is "broken beyond repair" and should be limited to home networks, not critical infrastructure 42:01.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, welcome everyone to our talk about uh the security of some EV chargers uh or the communication modms inside them. So this should be a really fun talk with some cool demos for you. So just first of all to get started, who are we and why do we feel qualified to actually talk to you today? So my name is Marcel. I'm a PhD student at the system security lab at the University of Oxford and I'm doing my PhD on the security of EV charging. Um, and in my work, I'm also supported by our colleagues at Armaswiss who give us some technical expertise and funding. And in my spare time, I get to do basically the same type of research, except I get to work on the kind of more fun projects that can't necessarily be put into a research paper. So, my name is Yan Barren. Um, I work as a red teamer a…