View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

XCharge EV Chargers Expose SSH with Default Root Credentials

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • XCharge EV Chargers Expose SSH with Default Root Credentials
    XCharge EV chargers allow root access via SSH over the CCS2 charging port using default credentials.
    • Applies to XCharge C6 EV chargers and potentially other vendors with similar configurations
    • Charging port acts as a network interface exposing SSH and Telnet services on all interfaces
    • Default root:root credentials with no authentication hardening enable immediate privileged access
    • Attack requires physical connection via CCS2 plug and low-cost hardware to exploit powerline communication
    • Compromise allows energy theft, charger manipulation, backdoors, lateral movement to CPO networks, and safety risks
      ๐Ÿ“Ž Coverage: saiflow.com ยท ๐Ÿ‘ via @campuscodi@mastodon.social

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check