EV Charging Cable's CCS2 Connector Exposes SSH Root Vulnerability
A significant security vulnerability has been discovered within the CCS2 connector used for electric vehicle charging. Lionel Richard Saposnik, a researcher at SaiFlow, found that the robust cable, which connects EVs to charging stations, carries not only electrical current but also network data. When a charging gun is connected to a vehicle, an IPv6 link is established between the car and the charging station using powerline communication over two pins of the CCS2 connector. This communication adheres to the ISO 15118 standard, facilitating negotiations regarding amperage, voltage, and the price per kilowatt-hour.
This discovery highlights a critical intersection of physical infrastructure and digital security in the rapidly expanding EV charging ecosystem. The reliance on established communication protocols like ISO 15118, while enabling essential functionality, can inadvertently create attack vectors if not rigorously secured. The potential for unauthorized access, even at a root level, through a physical charging interface raises concerns about data privacy, service integrity, and the overall security posture of connected vehicles and charging networks. Future development must prioritize end-to-end encryption and robust authentication mechanisms within these communication channels to mitigate risks as charging infrastructure becomes more integrated into smart grids and broader IoT networks.
AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.