CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Charger scan finds 720 of 1,000 exposed endpoints skip encryption

A probe of internet-reachable EV charging gear counted 1,000 management endpoints, with 720 accepting connections that skip encryption.

CarThreat Staff
Last updated: September 3, 2026 6:34 am
By
ctadmin
2 Min Read
SHARE

A passive probe of internet-facing EV charging equipment has counted 1,000 distinct management endpoints across 56 countries, and 720 of them accepted a connection with no transport-layer encryption. Threat intelligence firm Flare ran the scan and published the findings September 1.

The exposure sits in OCPP, the Open Charge Point Protocol that links a charger to its backend management system. The dominant version, OCPP 1.6 from 2015, has no built-in encryption, so traffic carrying authentication tokens, session commands and payment routing can cross the internet unprotected unless operators add VPNs or isolated cellular links.

Flare also found the risk concentrates on a few common platforms. The open-source SteVe management system, an embedded firmware stack without TLS and one commercial platform together account for about a third of the 1,000 endpoints. One vulnerable default setting can propagate across an entire fleet when hundreds of chargers share the same platform.

Past incidents show what that reach enables. Vandalism-style attacks redirected Isle of Wight chargers in 2022, an exposed Shell Recharge cloud database in 2023 spilled nearly a terabyte of logs and customer data, and roughly 116,000 records including VINs and authentication keys surfaced on a deep-web forum in 2024. A March 2026 CISA advisory described critical flaws in the Everon OCPP backend that could let attackers impersonate chargers and hijack sessions.

Flare’s prescriptions are familiar: move to OCPP 2.0.1 or newer with certificates, or VPNs for legacy hardware; pull management interfaces off the public internet; inventory charger platforms and firmware; remove default credentials; segment charging networks from business and payment systems; and monitor exposure passively. Adoption stalls because legacy OCPP 1.6 hardware keeps earning money and no single player owns the problem across the fragmented charger ecosystem.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Charging InfrastructureCybersecurityElectric Vehicles (EVs)Firmware SecurityOCPPThreat IntelligenceVulnerabilities
SOURCES:teiss
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

CybersecurityElectric Vehicles

E-rickshaw hacking scare exposes cybersecurity flaws in connected EVs

By
ctadmin
July 21, 2026
Cybersecurity

Generative AI Tools Heighten Vehicle Vulnerability Risks, South Korean Experts Warn

By
ctadmin
June 19, 2026
Cybersecurity

Nvidia Drive Hyperion Becomes Core Platform for Global Robotaxi Expansion

By
ctadmin
June 12, 2026
cel-shaded illustration of a small hatchback in an empty car-share bay with cyan data ribbons streaming away across the lot
Cybersecurity

Car-share service ties member record theft to one employee

By
ctadmin
September 16, 2026
Cybersecurity

EU Mandate for Driver Monitoring Raises Biometric Privacy in Connected Cars

By
ctadmin
July 12, 2026
Policy & Compliance

Senator widens AI camera inquiry to Axon, Verkada and Motorola Solutions

By
ctadmin
September 5, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?