• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-16-zero-days-on-first-day-of-pwn2own-automotive-2025/

Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 22, 2025
·
Updated

On the first day of Pwn2Own Automotive 2025, security researchers exploited 16 unique zero-days and collected $382,750 in cash awards. Fuzzware.io is leading the competition after hacking the Autel MaxiCharger and Phoenix Contact CHARX SEC-3150 electric vehicle chargers using a stack-based buffer overflow and an origin validation error bug. This earned them $50,000 and 10 Master of Pwn points. Sina Kheirkhah of Summoning Team also earned $91,750 and 9.25 Master of Pwn points after hacking the Ubiquiti and Phoenix Contact CHARX SEC-3150 EV chargers using a hard-coded cryptographic key bug and a combo of three zero-days (one of them previously known). Synacktiv Team is in third place on the leaderboard and took home $57,500 after successfully demoing a bug in the OCPP protocol to hack the ChargePoint Home Flex (Model CPH50) using signal manipulation through the connector, Security researchers from PHP Hooligans also successfully hacked a fully patched Autel charger using a heap-based buffer overflow and earned $50,000, while the Viettel Cyber Security team collected $20,000 after obtaining code execution on the Kenwood In-Vehicle Infotainment (IVI) using an OS command injection zero-day. After the zero-day vulnerabilities are exploited and reported during Pwn2Own, vendors have 90 days to develop and release security patches before TrendMicro's Zero Day Initiative publicly discloses them.

​The Pwn2Own Automotive 2025 hacking competition, which focuses on automotive technologie...

Read full article

Affected Software

10 affected components
Autel MaxiCharger
Phoenix Contact CHARX SEC-3150
Ubiquiti
ChargePoint Home Flex=Model CPH50
Kenwood In-Vehicle Infotainment
Autel charger
Tesla Wall Connector
Autel MaxiCharger
Phoenix Contact CHARX SEC-3150
ChargePoint Home Flex=Model CPH50
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What major event is reported in the article?

The article reports that hackers exploited 16 unique zero-day vulnerabilities during the first day of Pwn2Own Automotive 2025.

2

How much money was awarded to the hackers for their exploits?

The hackers collectively earned $382,750 in cash awards for their successful zero-day exploits.

3

What specific products were mentioned as being affected by the exploits?

The affected products include the Autel MaxiCharger, Phoenix Contact CHARX SEC-3150, ChargePoint Home Flex, Kenwood In-Vehicle Infotainment, and Tesla wall connector.

4

Which security research team is leading the competition?

Fuzzware.io is currently leading the Pwn2Own Automotive 2025 competition.

5

What type of vulnerabilities were exploited by the hackers?

The hackers exploited zero-day vulnerabilities, which are previously unknown security flaws.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203