Security Risks in an EV Charging Station.

This is what came out of pentesting a charging station: an exposed console port, a readable firmware image, a cloneable RFID card, and OCPP carrying it all. Findings first, then what to do about them.

IoT & Hardware

Automotive & EV

Hemant Sonkar
Pages:
25
Format:
PDF
Level:
Intermediate
Updated:
Oct 2026
Pages:
25
Format:
PDF
Level:
Intermediate
Updated:
Oct 2026

Key Takeaways

  • The hardware findings from a real assessment: UART and console port access, JTAG, firmware extraction from memory, and configuration review.
  • The user interface attack surface: RFID cloning, the display and touchscreen, and the companion mobile application.
  • OCPP explained properly: how it works, what changed across versions, and the vulnerabilities that persist in deployed implementations.
  • Which components matter inside a charging station and why, so you can scope an assessment before procurement rather than after deployment.

What's inside

Charger rollouts are moving faster than charger security. The unit is a computer with a payment interface, a radio link and a physical connection to a vehicle, deployed unattended in a public place, and often built on reference designs that were never assessed.

This ebook reports what a penetration test of a charging station actually surfaced: weak communication protocols, poor user authentication, and hardware access that should not have been reachable. Each finding is described with its impact, so operators and manufacturers can act on it rather than debate it.

What the 25 pages cover

01
Executive summary
p. 4
What the assessment found, and why it matters to operators and manufacturers
02
An introduction to EV chargers
p. 5
How a charging station is put together, in the terms an assessor needs.
03
Important components you should know
p. 6
The control unit, communication module, user interface and what each exposes.
04
Hardware vulnerabilities in the control unit
p. 9
UART and console ports, JTAG access, firmware extraction, and configuration review.
05
Vulnerabilities in the user interface
p. 15
RFID, the display and touchscreen, and the mobile application.
06
Vulnerabilities in the communication protocol
p. 19
OCPP: how it works, its versions, and the flaws that survive in deployment.
07
Conclusion and references
p. 22
What to fix first, and where to read further.

Look inside

A sample spread — the level of detail in every chapter.
Written by Payatu's IoT security practice
Lead Security Consultant heading Payatu's IoT tower. Has assessed medical devices, home automation and EVs, and regularly delivers IoT hacking trainings at Nullcon, c0c0n and null.
Dark background with a smooth, flowing red wave shape across the image.

Scope your charger assessment properly

The full 25-page PDF, with every finding, its impact, and the OCPP breakdown, written to be handed to the team building or operating the station.
Keep going

More from the Payatu library

Securing Salesforce: Pentesting and Config Review.
PDF:
59
pages
Cloud & SaaS
Securing Salesforce: Pentesting and Config Review.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Akanksha Prasad, Prajyot Chemburkar
All You Need to Know About the ISA/IEC 62443 Standard.
PDF:
36
pages
OT & ICS
All You Need to Know About the ISA/IEC 62443 Standard.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Amit Musale, Rohit Kumar
Cybersecurity Playbook for IPO-Bound Fintech Companies in India.
PDF:
38
pages
GRC & Compliance
Cybersecurity Playbook for IPO-Bound Fintech Companies in India.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Team Payatu