RomHack Camp 2026

Matthew

Mateusz Wójcik, an independent security researcher, red team operator, and former programmer specializing in IoT security, loves to find new vulnerabilities in IoT devices, especially those based on architectures like ARM and MIPS.


Session

10-03
12:30
40min
Breaking the Charge: Security Analysis of the Phoenix Contact CHARX SEC-3000 EV Charging Controller
Piotr Ptaszek, Matthew

Talk summary: Electric vehicle charging infrastructure is rapidly expanding, becoming a critical component of modern transportation. Despite the increased attention on its security, our research shows that even devices previously examined in competitions such as Pwn2Own can still hide impactful vulnerabilities.

We picked up this device right after Pwn2Own results were announced and the competition was over - and quickly found that the story was far from finished. Our security analysis of this commercially available Phoenix Contact CHARX SEC-3000 EV charging station controller uncovered serious, previously unknown issues that had gone unnoticed during the event. By combining firmware analysis with emulation techniques, we identified several critical vulnerabilities (including OS Injection) affecting the device. We will walk through the approaches, challenges, and what we have learned.

Longer talk description: This session provides a technical analysis into our ongoing research on an EV charging station controller. The device we investigated had already been part of a Pwn2Own competition, yet our analysis revealed multiple security vulnerabilities. We will cover our approach to analyzing the charger, including firmware extraction and emulation to understand internal components and logic of the device ecosystem.

Cybersecurity and Hacking
STAGE 1 (Section 9)