• News/
  • https://www.bleepingcomputer.com/news/security/tesla-ev-charger-hacked-twice-on-second-day-of-pwn2own-tokyo/

Tesla EV charger hacked twice on second day of Pwn2Own Tokyo

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 23, 2025
·
Updated

​Security researchers hacked Tesla's Wall Connector electric vehicle charger twice on the second day of the Pwn2Own Automotive 2025 hacking contest. They also exploited 23 more zero-day vulnerabilities in WOLFBOX, ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, and EMPORIA EV chargers, as well as in the Alpine iLX-507, Kenwood DMX958XR, Sony XAV-AX8500 In-Vehicle Infotainment (IVI) systems. PHP Hooligans were the first to crash the Tesla Wall Connector after using a Numeric Range Comparison Without Minimum Check zero-day bug to take over the device. They were followed by Synacktiv, who also hacked Tesla's EV charger via the Charging Connector, an approach that's never been demonstrated publicly before. Today, two bug collisions occurred during Tesla Wall Connector hacking attempts: one by team PCAutomotive and the other by the Summoning Team's Sina Kheirkhah, who used an exploit chain of two already-known bugs. According to the Pwn2Own Tokyo 2025 contest rules, all devices targeted during the competition must have all security updates installed and run the latest operating system versions. Trend Micro's Zero Day Initiative awarded $335,500 in cash rewards during the second day for 23 zero-day vulnerabilities. Sina Kheirkhah is currently in the lead for Master of Pwn.

​On the first day of Pwn2Own Automotive, security researchers exploited 16 unique zero-day vulnerabilities and collected $382,750 in cash awards. After the competition ends, vendors will have 9...

Read full article

Affected Software

17 affected components
Tesla Wall Connector
WOLFBOX
ChargePoint Home Flex
Autel MaxiCharger
Phoenix Contact CHARX
EMPORIA EV chargers
Alpine iLX-507
Kenwood DMX958XR
Sony XAV-AX8500
Tesla Wall Connector
ChargePoint Home Flex
Autel MaxiCharger
Phoenix Contact CHARX
EMPORIA EV chargers
Alpine iLX-507
Kenwood DMX958XR
Sony XAV-AX8500
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities were demonstrated at the Pwn2Own Tokyo event?

Security researchers hacked Tesla's Wall Connector and exploited 23 other zero-day vulnerabilities during the contest.

2

Which electric vehicle chargers were impacted by the hacks?

The affected products include Tesla Wall Connector, WOLFBOX, ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, EMPORIA EV chargers, Alpine iLX-507, Kenwood DMX958XR, and Sony XAV-AX8500.

3

What is the significance of the Pwn2Own competition for automotive security?

Pwn2Own serves as a platform to identify vulnerabilities in automotive technology, pushing manufacturers to enhance security measures.

4

How many successful hacks were reported on the second day of the event?

Two successful hacks of the Tesla Wall Connector were reported on the second day of Pwn2Own Tokyo.

5

What type of security measures should EV charger manufacturers consider following this event?

EV charger manufacturers should prioritize patching vulnerabilities and implementing robust security protocols to protect against future attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203