CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Charger scan finds 720 of 1,000 exposed endpoints skip encryption

A probe of internet-reachable EV charging gear counted 1,000 management endpoints, with 720 accepting connections that skip encryption.

CarThreat Staff
Last updated: September 3, 2026 6:34 am
By
ctadmin
2 Min Read
SHARE

A passive probe of internet-facing EV charging equipment has counted 1,000 distinct management endpoints across 56 countries, and 720 of them accepted a connection with no transport-layer encryption. Threat intelligence firm Flare ran the scan and published the findings September 1.

The exposure sits in OCPP, the Open Charge Point Protocol that links a charger to its backend management system. The dominant version, OCPP 1.6 from 2015, has no built-in encryption, so traffic carrying authentication tokens, session commands and payment routing can cross the internet unprotected unless operators add VPNs or isolated cellular links.

Flare also found the risk concentrates on a few common platforms. The open-source SteVe management system, an embedded firmware stack without TLS and one commercial platform together account for about a third of the 1,000 endpoints. One vulnerable default setting can propagate across an entire fleet when hundreds of chargers share the same platform.

Past incidents show what that reach enables. Vandalism-style attacks redirected Isle of Wight chargers in 2022, an exposed Shell Recharge cloud database in 2023 spilled nearly a terabyte of logs and customer data, and roughly 116,000 records including VINs and authentication keys surfaced on a deep-web forum in 2024. A March 2026 CISA advisory described critical flaws in the Everon OCPP backend that could let attackers impersonate chargers and hijack sessions.

Flare’s prescriptions are familiar: move to OCPP 2.0.1 or newer with certificates, or VPNs for legacy hardware; pull management interfaces off the public internet; inventory charger platforms and firmware; remove default credentials; segment charging networks from business and payment systems; and monitor exposure passively. Adoption stalls because legacy OCPP 1.6 hardware keeps earning money and no single player owns the problem across the fragmented charger ecosystem.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Charging InfrastructureCybersecurityElectric Vehicles (EVs)Firmware SecurityOCPPThreat IntelligenceVulnerabilities
SOURCES:teiss
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

CARS24 files complaint over 3,100 customer records sold to rival

By
ctadmin
September 6, 2026
Cybersecurity

Vehicles are getting their own offline AI brain thanks to FEV and Microsoft

By
ctadmin
July 12, 2026
Cybersecurity

NXP and Quanta Join Forces on Deterministic Zonal Network for SDVs

By
ctadmin
May 22, 2026
Cybersecurity

Chinese lidar faces federal review as lawmakers push bans

By
ctadmin
August 23, 2026
Electric Vehicles

Fake plug-and-charge stations bill EV owners for stranger fills

By
ctadmin
August 9, 2026
Policy & Compliance

Connected vehicle security act clears Senate committee hurdle

By
ctadmin
July 22, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?