ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Tesla EV charger hacked twice at Pwn2Own Automotive 2025 - Researchers uncover 23 Zero-Day vulnerabilities

Tokyo, Japan—Security researchers participating in the Pwn2Own Automotive 2025 hacking contest achieved significant breakthroughs on its second day by exploiting Tesla’s Wall Connector electric vehicle (EV) charger twice and discovering 23 zero-day vulnerabilities in various EV chargers and in-vehicle infotainment (IVI) systems.

 

The hacking event, held from January 22 to January 24 in Tokyo as part of the Automotive World conference, spotlights vulnerabilities in automotive technologies, including EV chargers, IVI systems, and car operating systems. All devices targeted during the contest run on their latest firmware with full security updates, adhering to strict contest rules.

 

On the second day, the team PHP Hooligans made history as the first to crash Tesla’s Wall Connector successfully. They leveraged a previously unknown Numeric Range Comparison Without Minimum Check zero-day vulnerability to gain control of the device. Soon after, Synacktiv followed with an innovative hack of Tesla’s EV charger, using an entirely new Charging Connector exploit that had never been publicly demonstrated.

 

Notably, two additional attempts to hack the Tesla Wall Connector resulted in bug collisions, meaning researchers independently discovered the same vulnerabilities. PCAutomotive and Summoning Team’s Sina Kheirkhah each exploited previously known bugs to demonstrate their attacks.

 

Beyond Tesla, researchers uncovered critical vulnerabilities across other devices, including the ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, WOLFBOX, and EMPORIA EV chargers. Key infotainment systems such as the Alpine iLX-507, Kenwood DMX958XR, and Sony XAV-AX8500 were also successfully compromised.

 

The competition awarded $335,500 on the second day, highlighting leading researchers like Sina Kheirkhah, who now leads the race for the coveted "Master of Pwn" title. The achievements followed an equally notable first day, which saw 16 unique zero-day exploits disclosed and $382,750 awarded.

 

Trend Micro’s Zero Day Initiative (ZDI), which organizes the Pwn2Own contests, requires hacked device vendors to release patches within 90 days after the competition ends. This ensures that the disclosed vulnerabilities are responsibly reported and rectified before public disclosure.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543