Not If, But When:並非是否發生,而是何時發生;EVSE 基礎設施中的資安風險

VicOne 網路威脅研究實驗室VicOne 網路威脅研究實驗室

VicOne 與美國移動力中心(American Center for Mobility, ACM)共同探討電動車供電設備(EVSE)不斷演變的威脅情勢,並提出保護電網邊緣安全的策略。

Automotive CybersecurityEV charging
Not If, But When:並非是否發生,而是何時發生;EVSE 基礎設施中的資安風險

With global electric vehicle (EV) adoption accelerating, electric vehicle supply equipment (EVSE) has become a critical component at the grid-edge and within modern mobility ecosystems. Yet, these networked systems, scattered across cities, highways, and homes, are often deployed without the hardened defenses typically found in enterprise IT networks. 

Figure 1. Attack surfaces in EVSE span hardware, firmware, communications, backend systems, and grid interfaces.

Figure 1. Attack surfaces in EVSE span hardware, firmware, communications, backend systems, and grid interfaces.


As EVSE integrates more deeply with national grids and digital payment systems, its expanding attack surface introduces new challenges for automotive cybersecurity, safety, and reliability. These risks are the focus ofElectric Vehicle Supply Equipment Cybersecurity: Threat Landscape and the Road Aheada report developed by VicOne in collaboration with the American Center for Mobility (ACM).


Key findings 

  • Large-scale cyberattacks on EVSE have yet to occur, but research and ethical hacking competitions have revealed numerous exploitable vulnerabilities. At the Pwn2Own Automotive contests alone, over 50 zero-day vulnerabilities were discovered across major EVSE brands.
  • Automotive threat intelligence platforms, such as VicOne’s xAurient, have observed a growing interest among cybercriminals targeting EVSE.
  • Coordinated attacks on charging networks could disrupt power stability and endanger consumers.
  • Compliance with standards is necessary, but it is not enough. A defense-in-depth strategy is required amid an evolving threat landscape. 

While major incidents targeting EVSE infrastructure remain rare, this should not be mistaken for security. The vulnerabilities are real, and cybercriminals are watching — it’s not a matter of if, but when. Strengthening EVSE defenses today is the only way to safeguard tomorrow’s connected infrastructure. 

Download “Electric Vehicle Supply Equipment Cybersecurity: Threat Landscape and the Road Ahead” to gain deeper insights into the evolving EVSE threat landscape and the strategies to mitigate them. 

Download VicOne Whitepaper: Securing the Charge: The Hidden Risks in ISO 15118

About the Author

VicOne 網路威脅研究實驗室
VicOne 網路威脅研究實驗室

VicOne 資安威脅研究實驗室(CyberThreat Research Lab)致力於探索聯網車輛、軟體定義車輛(SDV)、電動車充電基礎設施(EV Charging Infrastructure)及 Physical AI 系統所面臨的新興威脅與風險。研究範疇涵蓋零日漏洞(Zero-Day Vulnerability)發掘、深網與暗網威脅情資分析、Auto-ISAC Automotive Threat Matrix(ATM)威脅模型對應,以及 AI 安全風險分析等領域。實驗室研究成果曾於 RSAC、ESCAR USA、ELIV 等國際產業論壇發表,並獲 Auto-ISAC 等國際組織引用與參考。透過持續的威脅研究與情資分析,VicOne 資安威脅研究實驗室協助汽車製造商(OEM)、供應商、產品安全事件應變團隊(PSIRT)及車聯網安全決策者,將技術洞察轉化為可執行的防禦策略與風險管理措施,提升整體資安韌性。