Hacking EV Chargers: From Bluetooth to Contactor

by Brendan Scarvell | - 4:30pm

What happens when you buy an EV charger off the shelf and start pulling it apart? Turns out, quite a lot.

This talk walks through the full-stack compromise of a commercial EV charger built on a widely deployed firmware platform used by multiple resellers worldwide. Starting with the installation guide (which helpfully prints the default passwords for you), we work through firmware extraction, binary reverse engineering in Ghidra, and the discovery of multiple pre-auth remote code execution vulnerabilities across the device’s attack surface - including one accessible via Bluetooth from a car park with no network access required.

But getting a shell was just the beginning. The deeper we looked at what was running inside the charger, the more the findings shifted from traditional cybersecurity into something more concerning - direct, unauthenticated access to the physical safety mechanisms that prevent people from getting hurt.

We’ll cover the full research journey, including the part where we bricked the first charger and had to buy another one, a vendor relationship that went from radio silence to office visits, and what this research reveals about the gap between cybersecurity and electrical safety in the EV charging industry.

Expect Ghidra, live demos, relay clicks, memes, and a conversation about what it means when safety-critical infrastructure is built like consumer IoT.

This talk is suitable for anyone interested in IoT security, embedded systems, hardware hacking, vulnerability research, or the intersection of cybersecurity and physical safety.

About Brendan Scarvell

Brendan is a security researcher and co-founder of Signal 11, with a background spanning web application, network, hardware, and embedded device security. His work focuses on finding and exploiting vulnerabilities in real-world systems, with a particular interest in connected devices and the security risks created when consumer and business infrastructure overlap.

Other talks