EV Charger Penetration Testing
Secure your EV charging infrastructure against cyber threats. Residential chargers, public stations, and backend management systems.
What Is EV Charger Penetration Testing?
EV charger penetration testing evaluates the security of electric vehicle supply equipment (EVSE). Covers residential wallboxes, public DC/AC charging stations, charging station management systems (CSMS), mobile apps, and payment terminals.
As EV adoption accelerates across APAC, charging infrastructure has become a critical attack surface. A compromised station can disrupt service, steal payment data, or pivot into the power grid operator's network. Manufacturers, charge point operators, and fleet operators all carry this risk.
Scope of an EV Charger Pentest
Every component in the charging ecosystem.
Charging Stations
AC/DC charging units, smart chargers, fast-charging stations. Firmware exploits, authentication bypass, OCPP message manipulation.
CSMS Backend
Charging Station Management System. API vulnerabilities, authentication weaknesses, tenant isolation in multi-operator environments.
OCPP Protocol
Open Charge Point Protocol implementation testing. Message injection, replay attacks, downgrade attacks between OCPP 1.6 and 2.0.1.
Payment Systems
EMV, NFC, QR-based payment flows. Transaction manipulation, card data exposure, payment terminal firmware assessment.
Mobile Apps
Companion apps for EV drivers. API testing, authentication bypass, session hijacking, insecure data storage.
Grid Integration
The boundary between charging infrastructure and power grid. DER integration, load management manipulation, grid-side exposure.
Testing Approaches
Two methodologies for different deployment stages.
Grey Box
Non-intrusive assessment of deployed chargers. Protocol analysis, configuration review, API testing. Best for operational environments where uptime is critical.
Best for: Operational charging networks where service continuity is non-negotiable.
White Box
Full access assessment. Firmware reverse engineering, hardware interface testing (UART, JTAG), source code review. Best for pre-deployment and compliance validation.
Best for: Pre-deployment validation, compliance testing, hardware certification.
Our Approach
Safety and service continuity come first.
Safe Reconnaissance
Asset discovery, OCPP version identification, network topology mapping, RF and wireless survey. We map the environment without disrupting service.
Vulnerability Discovery
Firmware analysis, protocol fuzzing, API testing, hardware interface probing. Every attack surface mapped against real-world threat models.
Controlled Exploitation
Proof-of-concept against staging units or during maintenance windows. Never against live public infrastructure. Every test designed to demonstrate impact without disruption.
Operational Reporting
Findings mapped to ISO 15118, IEC 62443, and CRA requirements. Risk rated by operational and safety impact. Engineering-ready remediation guidance included.
Our Technical Expertise
Deep specialisation in EV charging security.
ISO 15118
International standard for EV charging communication. PnC (Plug and Charge), certificate management, TLS implementation review.
IEC 62443
Industrial security framework applied to charging infrastructure. Zones, conduits, security levels assessed against the standard.
OCPP Expertise
Deep knowledge of OCPP 1.6, 2.0.1, and Open CPM. Protocol-level attack vectors and implementation flaws that generic testing misses.
Hardware Security
UART, JTAG, SPI debugging. Firmware extraction and analysis. Side-channel assessment of charger controller boards.
Request an EV Charger Pentest
Tell us about your charging infrastructure. We'll scope a safe, controlled engagement.