• News/
  • https://www.darkreading.com/vulnerabilities-threats/tesla-gear-hacked-multiple-times-pwn2own-contests

Tesla Gear Gets Hacked Multiple Times in Pwn2Own Contests

Dark Reading
·
Kristina Beek
·
Published Jan 23, 2025
·
Updated

NEWS BRIEF Researchers at the this year's Pwn2Own Automotive hacking contest successfully hacked Tesla's wall connector electric vehicle (EV) charger. The annual contest focuses on hacking automotive technologies during the Automotive World tradeshow in Tokyo. The contest allows researchers to target car operating systems, electric vehicles, chargers, and infotainment systems in vehicles to uncover hidden vulnerabilities and potential threats. Zero Day Initiative said the PHP Hooligans used a "numeric range comparison without minimum check" zero-day bug to take over the EV charger and crash it. This feat earned them $50,000 in prize money and five Master of Pwn points. Right behind them was Synacktic, which hacked the Tesla EV charger through the charging connector. The PHP Hooligans also exploited 23 other zero-day vulnerabilities in WOLFBOX, ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, and EMPORIA EV chargers. On day two of the contest, Trend Micro's Zero Day Initiative paid out $718,250 in rewards to onsite security researchers who discovered 39 unique zero-days. Sina Kheirkhah is currently leading the Pwn2Own contest with 24.5 points, followed by Synacktiv in second place, and PHP Hooligans in third.

Read full article

Affected Software

11 affected components
Tesla wall connector electric vehicle (EV) charger
WOLFBOX EV chargers
ChargePoint Home Flex
Autel MaxiCharger
Phoenix Contact CHARX
EMPORIA EV chargers
Tesla Wall Connector
ChargePoint Home Flex
Autel MaxiCharger
Phoenix Contact CHARX
EMPORIA EV chargers
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses instances of Tesla's wall connector EV charger being hacked at the Pwn2Own Automotive hacking contest.

2

What security implications are discussed in this article?

The article highlights the vulnerabilities in electric vehicle charging systems that could be exploited by attackers.

3

What products or software are affected by these hacks?

The affected products include Tesla wall connector EV charger, WOLFBOX EV chargers, ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, and EMPORIA EV chargers.

4

Who conducted the hacking demonstrations?

The hacking demonstrations were conducted by researchers participating in the annual Pwn2Own Automotive contest.

5

What is the significance of the Pwn2Own contest in relation to automotive technologies?

Pwn2Own is significant as it focuses on exposing vulnerabilities in automotive technologies, thereby prompting improvements in security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203