Hasty Briefsbeta

Bilingual

SSH with default credentials found in CCS2 Chargers

21 hours ago
  • XCharge C6 EV chargers expose SSH and Telnet services on all network interfaces, including the CCS2 charging port, with default credentials root:root, allowing immediate root access to anyone who plugs in a malicious EV.
  • The attack requires only $130 in hardware (CCS2-compatible device, PLC modem, Raspberry Pi) and physical access to the charging port, enabling energy theft, device manipulation, and potential pivot to the CPO's private network.
  • The vulnerability pattern (services bound to 0.0.0.0, weak/default credentials, no authentication hardening) is common across the EV charging industry, and the exposed services on CCS2 could become a ticking time bomb if future CVEs eliminate the need for credentials.
  • Recommendations for CPOs include immediate firmware updates, monitoring for abnormal SLAC/V2G communication, and network segmentation; vendors should generate unique credentials per device and bind administrative services only to management interfaces.