Weak security means attackers could disable all of a city's public EV chargers
ID: 3275c7b6-5aa3-5f38-acb9-05e4ca05f143
STIX ID: report--3275c7b6-5aa3-5f38-acb9-05e4ca05f143
Feed Name: The Register (Security)
Hetian Shi presented research at Black Hat Asia revealing widespread security weaknesses in rentable IoT services (public EV chargers, shared bikes/scooters). He found exposed debug/UART ports, shared authentication keys in firmware, and backend/app authentication flaws that allow phantom clients to charge or rent for free and enable remote disabling of devices. Using a tool called IDScope he demonstrated disabling a publicly listed EV charger in a live demo and reported similar issues in European apps, suggesting the flaws could enable large-scale denial-of-service and privacy exposure across multiple cities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
