started · updated
Tesla charger vulnerability used to create four-vendor EV worm
Security researchers Tobias Scharnowski and Kristian Covic of Fuzzware.io have demonstrated a wormable exploit chain that targets electric vehicle (EV) charging infrastructure. Presented at the Black Hat USA conference, the exploit begins with a single connection to a Tesla Universal Wall Connector and spreads autonomously without operator input.
The researchers successfully moved the malware from the Tesla Wall Connector firmware to an Alpine infotainment unit via Wi-Fi. From there, the exploit spread to an Autel MaxiCharger and a ChargePoint Home Flex using wireless Bluetooth. The vulnerability was discovered by using software emulation, or ‘rehosting,’ to test the Wall Connector firmware at high speeds, bypassing the difficulties of manual hardware fuzzing.
Tesla Charging confirmed the existence of the bug, stating it was patched in late 2025 and has already been deployed to its fleet of chargers.
Entities
Alpine · Autel · ChargePoint · Fuzzware.io · Tesla