EV Charger Penetration Testing
05A — EV CHARGER PENTEST

EV Charger Penetration Testing

Secure your EV charging infrastructure against cyber threats. Residential chargers, public stations, and backend management systems.

What Is EV Charger Penetration Testing?

EV charger penetration testing evaluates the security of electric vehicle supply equipment (EVSE). Covers residential wallboxes, public DC/AC charging stations, charging station management systems (CSMS), mobile apps, and payment terminals.

As EV adoption accelerates across APAC, charging infrastructure has become a critical attack surface. A compromised station can disrupt service, steal payment data, or pivot into the power grid operator's network. Manufacturers, charge point operators, and fleet operators all carry this risk.

Scope of an EV Charger Pentest

Every component in the charging ecosystem.

Charging Stations

AC/DC charging units, smart chargers, fast-charging stations. Firmware exploits, authentication bypass, OCPP message manipulation.

CSMS Backend

Charging Station Management System. API vulnerabilities, authentication weaknesses, tenant isolation in multi-operator environments.

OCPP Protocol

Open Charge Point Protocol implementation testing. Message injection, replay attacks, downgrade attacks between OCPP 1.6 and 2.0.1.

Payment Systems

EMV, NFC, QR-based payment flows. Transaction manipulation, card data exposure, payment terminal firmware assessment.

Mobile Apps

Companion apps for EV drivers. API testing, authentication bypass, session hijacking, insecure data storage.

Grid Integration

The boundary between charging infrastructure and power grid. DER integration, load management manipulation, grid-side exposure.

Testing Approaches

Two methodologies for different deployment stages.

Grey Box

Non-intrusive assessment of deployed chargers. Protocol analysis, configuration review, API testing. Best for operational environments where uptime is critical.

Best for: Operational charging networks where service continuity is non-negotiable.

White Box

Full access assessment. Firmware reverse engineering, hardware interface testing (UART, JTAG), source code review. Best for pre-deployment and compliance validation.

Best for: Pre-deployment validation, compliance testing, hardware certification.

Our Approach

Safety and service continuity come first.

01

Safe Reconnaissance

Asset discovery, OCPP version identification, network topology mapping, RF and wireless survey. We map the environment without disrupting service.

02

Vulnerability Discovery

Firmware analysis, protocol fuzzing, API testing, hardware interface probing. Every attack surface mapped against real-world threat models.

03

Controlled Exploitation

Proof-of-concept against staging units or during maintenance windows. Never against live public infrastructure. Every test designed to demonstrate impact without disruption.

04

Operational Reporting

Findings mapped to ISO 15118, IEC 62443, and CRA requirements. Risk rated by operational and safety impact. Engineering-ready remediation guidance included.

Our Technical Expertise

Deep specialisation in EV charging security.

ISO 15118

International standard for EV charging communication. PnC (Plug and Charge), certificate management, TLS implementation review.

IEC 62443

Industrial security framework applied to charging infrastructure. Zones, conduits, security levels assessed against the standard.

OCPP Expertise

Deep knowledge of OCPP 1.6, 2.0.1, and Open CPM. Protocol-level attack vectors and implementation flaws that generic testing misses.

Hardware Security

UART, JTAG, SPI debugging. Firmware extraction and analysis. Side-channel assessment of charger controller boards.

Request an EV Charger Pentest

Tell us about your charging infrastructure. We'll scope a safe, controlled engagement.

Get in Touch