Lead story
One Tesla Charger Bug to Worm Them All: Researchers Build a Four-Vendor EV Exploit Chain
Electric vehicle charging infrastructure has a dirty secret: it's networked, it's often under-patched, and — as researchers demonstrated at Black Hat 2026 this week — a single firmware vulnerability in one vendor's charger can be chained into a worm that spreads across four different manufacturers' equipment.
The research team started with a bug in Tesla's charging hardware. By rehosting the extracted firmware in a lab environment, they were able to reverse-engineer the vulnerability and craft an exploit. That part alone would have been newsworthy. But the team went further, chaining the Tesla flaw with weaknesses in three other EV charging vendors to produce a worm capable of propagating autonomously across co-located or networked charging stations.
The implications are serious. Public charging infrastructure isn't a collection of isolated units — chargers at the same site share backend management networks, and many are remotely managed through the same cloud platforms. A worm that can hop between vendors doesn't need a particularly large entry point; it just needs one charger on one network to be exposed.
What could an attacker actually do with this? The options range from financially disruptive to genuinely dangerous. Disabling charging stations in bulk — think a fleet operator's depot or a motorway service corridor — causes immediate logistical harm. Manipulating billing systems creates fraud opportunities at scale. And in a worst-case scenario, researchers have previously shown that compromised chargers can send malformed power signals that damage vehicle onboard systems.
The research was disclosed at Black Hat, which means the vendors involved were given advance notice and the team followed coordinated disclosure norms. The researchers haven't published the full exploit chain publicly. But the proof of concept was demonstrated live, and the core technique — rehosting embedded firmware to find bugs before weaponising them — is not novel. Other researchers can and will attempt to replicate this.
Why now? EV charging rollout has been treated primarily as an infrastructure and logistics problem, not a cybersecurity one. Procurement decisions have prioritised cost and charging speed. Security certifications for EV chargers remain a patchwork globally — the EU's Network and Information Security 2 directive is beginning to cover some of this ground, but implementation is uneven.
Australia is particularly exposed here. The federal government's National Electric Vehicle Strategy has accelerated charging infrastructure rollout along major highway corridors and in urban centres, but there is no specific mandatory cybersecurity standard for EV charger firmware at the time of writing. The ACSC's critical infrastructure uplift work has focused primarily on energy generation and transmission, not charging endpoints. That gap is worth closing before someone closes it for us.
Watch for: vendor patch timelines, whether the four affected manufacturers publicly disclose CVEs, and whether any charging network operators trigger SOCI Act incident reporting obligations if they classify their infrastructure as critical. The chargers are the new edge device — and we've seen how that story goes.
