CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Ethernet flood via OBD port stalls cars and blacks out displays

A rogue DHCP server on the OBD Ethernet port lets attackers flood a car's network and disrupt safety-critical systems, researchers will show at DEF CON 34.

CarThreat Staff
Last updated: August 6, 2026 8:54 pm
By
ctadmin
2 Min Read
SHARE

Researchers will demo a new attack on production vehicles at the Car Hacking Village during DEF CON 34 that turns a car’s diagnostic port into a weapon against its own safety systems.

Modern cars are moving diagnostics from CAN to Automotive Ethernet, and gateway ECUs are supposed to limit traffic to specific IP addresses. The problem, says researcher Yehyeong Lee, is that many gateways also run DHCP so diagnostic tools can connect. Anyone with brief access to the diagnostic socket can stand up a rogue DHCP server, seize control of the gateway’s IP assignment, and then attack the network blind, with no map of the vehicle’s internals required.

The researchers blast the network with high-rate Layer 2 and Layer 3 traffic across ARP, ICMP, UDP, and TCP. The flood wrecks safety-critical functions such as the audio-visual navigation unit, wipers, and headlights, and can bring the vehicle to an abrupt stop once the driver selects Drive or Reverse. Crank the packet rate higher and the infotainment screen goes dark, refusing to come back until the vehicle is completely powered off.

The findings were discovered on a production vehicle, and the team will bring a live demo to the village’s Creator Stage on Saturday afternoon.

The work highlights a growing tension in vehicle design: the same Ethernet backbone that enables modern diagnostics and software updates also hands attackers a high-bandwidth path into safety systems when network services are left open. OEMs should treat diagnostic ports as untrusted, disable unused services, and add rate limiting and authentication to in-vehicle network stacks.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Automotive EthernetConnected VehiclesCybersecurityDEF CON 34ECU SecurityOBD-IIVulnerabilities
SOURCES:Car Hacking Village
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Fuzzing tool finds denial-of-service bug in V2X message gateways

By
ctadmin
August 13, 2026
Cybersecurity

Belgium becomes first in Europe to say yes to driverless cars on public highways

By
ctadmin
July 12, 2026
PCA finds 345 auto vulnerabilities as high-severity flaws double
Cybersecurity

PCA finds 345 auto vulnerabilities as high-severity flaws double

By
ctadmin
August 1, 2026
CybersecurityResearch & Innovation

EvilValet attack uses AOSP test keys to compromise Honda infotainment

By
ctadmin
July 21, 2026
Cybersecurity

Uber Invests $500M in Nuro Robotaxi Deal with Lucid Vehicles

By
ctadmin
June 12, 2026
Cybersecurity

Researchers weaponize digital license plates against plate readers

By
ctadmin
August 10, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?