CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Car NewsCybersecurity

Critical buffer overflow in EV charging protocol puts vehicles at risk

A stack-based buffer overflow in the SLAC protocol implementation affects both EVs and charging stations.

CarThreat Staff
Last updated: July 18, 2026 7:20 am
By
ctadmin
2 Min Read
SHARE

PlaxidityX researchers have disclosed a critical stack-based buffer overflow vulnerability in the open-source implementation of the Signal Level Attenuation Characterization protocol used in EV charging communication. Tracked as CVE-2025-27071, the flaw resides in the open-plc-utils toolkit that implements the SLAC protocol defined by ISO 15118 and DIN SPEC 70121.

Both electric vehicles and charging stations are affected. The vulnerability allows an attacker to trigger arbitrary code execution by sending a crafted packet where the “Number of Groups” field is not validated before being used in a memcpy operation, creating a stack-based buffer overflow.

The SLAC protocol ensures reliable Powerline Communication between EVs and charging stations, handling the handshake process before IP communication begins. The open-plc-utils project provides tools for interacting with Qualcomm Atheros Powerline chips, making the vulnerable code present in many charging station implementations that run on Linux.

PlaxidityX reported the issue to Qualcomm in December 2024, leading to a security advisory in August 2025 and a subsequent patch. The vulnerability was found in both the EV side and the charging station side of the protocol implementation.

As EV adoption grows alongside Vehicle-to-Grid integration, securing protocol implementations becomes critical. This finding highlights the need for rigorous memory-safety validation in charging infrastructure firmware, where a single unvalidated byte can cascade into full system compromise.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Automotive Attack SurfaceBuffer OverflowCISAEV ChargingEV Charging Security
SOURCES:CISA
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Microchip Adds FOTA and Key Management ICs to Meet Automotive Cyber Regulations

By
ctadmin
June 19, 2026
Cybersecurity

Deterministic ECU Protection: Preventing Exploits Without Redesigning CAN Bus Communication

By
ctadmin
May 22, 2026
Cybersecurity

Ecarx and May Mobility Partner on Level 4 Computing for Robotaxi Fleet

By
ctadmin
May 22, 2026
Cybersecurity

US automakers scramble to strip Chinese parts from connected cars

By
ctadmin
July 24, 2026
Cybersecurity

Automotive Cyber Vulnerabilities Double Year Over Year as Attacks Get Easier

By
ctadmin
July 1, 2026
CybersecurityElectric Vehicles

E-rickshaw hacking scare exposes cybersecurity flaws in connected EVs

By
ctadmin
July 21, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?