DEF CON 3 3 - Exploiting Vulns in EV Charging Comms - Jan Berens, Marcell Szakály, Sebastian Köhler @DEFCONConference
DEF CON 3 3 - Exploiting Vulns in EV Charging Comms - Jan Berens, Marcell Szakály, Sebastian Köhler  @DEFCONConference
Uploaded October 2025 | Updated September 2026, 3 weeks ago
In this talk we present a collection of attacks against the most widely used EV charging protocol, by exploiting flaws in the underlying power-line communication technologies affecting almost all EVs and chargers.

Specifically, we target the QCA 7000 Homeplug modem series, used by the two most popular EV charging systems, CCS and NACS.

We demonstrate multiple new vulnerabilities in the modems, enabling persistent denial of service.

To better understand the scope of these issues, we conduct a study of EV chargers and vehicles, and show widespread insecurities in existing deployments.

We show a variety of practical real-world scenarios where the HomePlug link can be used to hijack EV charging communications, even at a distance.

Finally, we present results from reverse engineering the firmware and how we can gain code execution.
DEF CON 3 3 - Exploiting Vulns in EV Charging Comms - Jan Berens, Marcell Szakály, Sebastian KöhlerDEF CON 32 - Social Engineering Like you’re Picard - Jayson E  StreetDEF CON 32 - Encrypted newspaper ads in the 19th century - Elonka Dunin, Klaus SchmehDEF CON 32 - Physical OSINT - Lukas McCulloughDEF CON 33 - Building the first open source hackable Quantum Sensor - Mark Carney, Victoria  KumaranDEF CON 33 - Private, Private, Private   Access Everywhere - Meghan JacquotDEF CON 32 - Abusing Windows Hello Without a Severed Hand  - Ceri Coburn, Dirk jan MollemaDEF CON 33 - BiC Village - The Truth, Whole Truth and Nothing b/t Truth of Cybersec - Louis DeweaverDEF CON 33 - Regex For Hackers - Adam BuildHackSecure Langley, Ben nahamsec SadeghipourDEF CON 23 - IoT Village - Wesley Wineberg - Cameras Thermostats and Home Automation ControllersDEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojpDEF CON 33 - Recording PCAPs from Stingrays With a $20 Hotspot - Cooper Quintin, oopsbagel
DEFCONConference |

DEF CON 3 3 - Exploiting Vulns in EV Charging Comms - Jan Berens, Marcell Szakály, Sebastian Köhler

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER