Listen to this Post
2025-01-23
The world of automotive cybersecurity was put to the test during Pwn2Own Automotive 2025, where elite researchers demonstrated their skills in uncovering critical vulnerabilities in vehicle systems. With a staggering $718,250 awarded over two days, the event highlighted the growing importance of securing modern vehicles against sophisticated cyber threats. From electric vehicle (EV) chargers to infotainment systems, hackers showcased their ability to exploit zero-day vulnerabilities, earning hefty rewards and recognition in the process.
Day 2 Highlights: A Deep Dive into Exploits and Rewards
On Day 2 of Pwn2Own Automotive 2025, organizers awarded $335,500, bringing the total prize pool to $718,250. Researchers demonstrated 39 unique zero-day vulnerabilities, underscoring the critical need for robust security measures in automotive technology.
Leading the charge was Sina Kheirkhah (@SinSinology) from the Summoning Team (@SummoningTeam), who chained two vulnerabilities to exploit the WOLFBOX charger. This feat earned the team $50,000 and 5 Master of Pwn points, solidifying their position at the top of the leaderboard.
The PHP Hooligans team also made waves by exploiting a Tesla Wall Connector bug, crashing and taking over the system. Their efforts were rewarded with $50,000 and 5 Master of Pwn points. Meanwhile, Synacktiv leveraged a logic bug in their exploit chain to hack the Tesla Wall Connector via the Charging Connector, earning $45,000 and 7 Master of Pwn points.
HT3 Labs (@ht3labs) demonstrated their expertise by chaining a missing authentication bug with an OS command injection issue to exploit the Phoenix Contact CHARX. Their work earned them $25,000 and 5 Master of Pwn points.
Day 1 of the event was equally impressive, with Trend Micro’s Zero Day Initiative (ZDI) awarding $382,750 for 16 unique zero-day exploits targeting infotainment systems, EV chargers, and automotive operating systems. Notably, despite a $500,000 reward offered for an autopilot exploit, no attempts were made to demonstrate vulnerabilities in a Tesla vehicle.
The complete results of Day 2 are available for those interested in the finer details of the exploits and rewards.
What Undercode Say:
The Pwn2Own Automotive 2025 event is more than just a competition; it’s a critical reflection of the state of automotive cybersecurity. As vehicles become increasingly connected and reliant on software, the potential attack surface for malicious actors grows exponentially. The exploits demonstrated at Pwn2Own highlight both the ingenuity of ethical hackers and the vulnerabilities that manufacturers must address to ensure consumer safety.
The Growing Importance of Automotive Cybersecurity
Modern vehicles are no longer just mechanical machines; they are complex computers on wheels. Infotainment systems, EV chargers, and autonomous driving features all rely on software, making them susceptible to cyberattacks. The fact that researchers were able to exploit 39 unique zero-day vulnerabilities in just two days is a wake-up call for the automotive industry.
The Role of Ethical Hacking
Events like Pwn2Own play a crucial role in identifying and mitigating vulnerabilities before they can be exploited maliciously. By incentivizing ethical hackers to uncover flaws, manufacturers can patch weaknesses and improve the overall security of their systems. The $718,250 awarded during the event is a small price to pay compared to the potential damage of a real-world cyberattack.
Tesla’s Resilience and the Autopilot Challenge
One of the most intriguing aspects of Pwn2Own Automotive 2025 was the lack of attempts to exploit Tesla’s autopilot system, despite the $500,000 reward. This could indicate that Tesla’s security measures are robust enough to deter even the most skilled hackers—or that the challenge was too complex to tackle within the event’s timeframe. Either way, it underscores the importance of continuous innovation in automotive cybersecurity.
The Future of Automotive Security
As the automotive industry continues to evolve, so too must its approach to cybersecurity. Manufacturers must adopt a proactive stance, integrating security into the design and development process rather than treating it as an afterthought. Collaboration with ethical hackers and participation in events like Pwn2Own will be essential in staying ahead of emerging threats.
In conclusion, Pwn2Own Automotive 2025 serves as both a celebration of ethical hacking and a stark reminder of the vulnerabilities that exist in modern vehicles. By addressing these challenges head-on, the automotive industry can pave the way for a safer, more secure future on the road.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Pwn2Own Automotive 2025)
References:
Reported By: Securityaffairs.com
https://www.reddit.com
Wikipedia: https://www.wikipedia.org
Undercode AI: https://ai.undercodetesting.com
Image Source:
OpenAI: https://craiyon.com
Undercode AI DI v2: https://ai.undercode.help




