EV charging security ISO 15118

Urgent Security Warning: Patch EV Chargers and TropOS

Category: Cybersecurity

Cybersecurity threats aren’t just hitting laptops and cloud servers anymore. They’re now targeting the systems that move cars, power cities, and keep businesses running behind the scenes. On October 30, 2025, CISA released two new advisories covering serious vulnerabilities in industrial control systems (ICS). These updates affect electric vehicle chargers and wireless network devices used in critical infrastructure. If that sounds technical, don’t worry, this breakdown keeps it simple, practical, and focused on what matters to real users and organizations.

What These New ICS Alerts Are Really About

Industrial control systems run the physical world; traffic lights, power grids, manufacturing lines, and now electric vehicle chargers. When a weakness is found, it isn’t just “another software bug.” It’s a door into real, physical systems.

CISA’s new alerts cover two major issues:

  1. ISO 15118-2 EV Charging Vulnerability:

A design flaw in the communication protocol used between electric cars and chargers could let attackers insert themselves into the data stream (a “man-in-the-middle” attack).

  1. Hitachi Energy TropOS Wireless Device Vulnerabilities:

Multiple flaws that allow attackers to inject commands, escalate privileges, and even gain full root access to devices used in energy and manufacturing networks.

Type of Security Issue:

Industrial Control System (ICS) vulnerabilities / exploitation of device-level weaknesses

Specifically:

SystemIssue TypeSecurity Category
ISO 15118 EV ChargersMan-in-the-Middle (MitM) via protocol weaknessCommunication tampering / endpoint spoofing
Hitachi TropOS DevicesCommand Injection + Privilege EscalationRemote code execution (RCE) + unauthorized root access

Why this matters:

These systems aren’t sitting in tech labs. They’re on highways, factory floors, utility stations, and public networks, often connected to the internet, often under-secured.

Quick Takeaways:

  • EV chargers can be wirelessly spoofed if security isn’t upgraded.
  • TropOS devices can be taken over remotely if not patched.
  • Both advisories recommend immediate updates, network isolation, and stronger encryption.

If your business runs EV charging networks or industrial wireless systems, stop assuming “it’s handled.” Ask your tech team today: Have we patched these?

Relevant Source (CISA): International Standards Organization ISO 15118-2

  • Provides official details on the EV charging protocol weakness, potential man-in-the-middle impact, and required mitigations (e.g., TLS under ISO 15118-20).

Relevant Source (CISA): Hitachi Energy TropOS

  • Outlines the TropOS command injection and privilege escalation vulnerabilities, affected firmware, and patch guidance to 8.9.7.0.
EV charger security ISO 15118 TropOS

Breaking It Down: The ISO 15118-2 EV Charger Flaw

The ISO 15118-2 standard controls how electric vehicles and charging stations talk to each other. The flaw comes from weak restrictions on who can join the communication channel. Attackers nearby can interfere, fake charger signals, steal data, or inject malicious instructions.

Risk Score: 7.2 (CVSS v4) – High
Impact: EV chargers may send or receive altered data without users knowing.
Attack Method: Wireless, close-range, electromagnetic spoofing.

What the Experts Recommend

  • Use TLS encryption (required in the newer ISO 15118-20 standard).
  • Validate device certificates, no certificate chain, no trust.
  • Isolate charging networks behind firewalls.
  • Never leave EV supply equipment exposed directly to the internet.

EV charging is now part of the critical transportation ecosystem. One exploited charger isn’t just a broken outlet, it could affect billing, grid load, or even large-scale traffic infrastructure.

Own or manage EV chargers? Upgrade to the ISO 15118-20 security model. Don’t wait for the breach headline.

Relevant Source (CISA): International Standards Organization ISO 15118-2

  • Provides the official vulnerability summary for CVE-2025-12357, impact of SLAC-based MitM, and recommended mitigations including TLS adoption and network isolation.

Relevant Source (IEC): ISO 15118-20:2022

  • Details the next-gen EV/EVSE communication standard that formalizes secure messaging and TLS use, providing the upgrade path recommended by CISA for hardened charging sessions.

Breaking It Down: Hitachi TropOS Device Exploits

What Is the Issue?

Hitachi TropOS devices are used for secure wireless networking in energy grids, automation systems, and manufacturing networks. Three different vulnerabilities allow attackers to:

  • Inject operating system commands
  • Escalate from normal user to full root access
  • Modify configurations to take full device control

Risk Score: Up to 8.7 – Very High
Impact: Full device compromise can disrupt operations, enable data theft, and create safety hazards.
Attack Method: Remote, low complexity, authenticated attacker

Once an attacker gains root access, the device stops being “equipment” and becomes an entry point. From there, they can:

  • Kill or reroute network traffic
  • Install persistent malware
  • Pivot deeper into control systems

Vendor Response

  • Patch immediately to firmware 8.9.7.0 or newer
  • Segment the network so TropOS devices aren’t reachable from public internet
  • Treat every user, laptop, and USB drive as a potential infection source

TropOS Do/Don’t Checklist

  1. Patch to latest firmware
  2. Restrict SSH access
  3. Use firewalls with minimal open ports
  4. Don’t browse the internet from control systems
  5. Don’t allow shared USB drives on ICS hardware

Relevant Source (CISA): Hitachi Energy TropOS

  • Official CISA bulletin detailing the TropOS vulnerabilities (CVE-2025-1036/1037/1038), affected firmware, severity (up to CVSS v4 8.7), and mitigation guidance including updating to 8.9.7.0 and network segmentation.

Relevant Source (Hitachi Energy): Multiple Vulnerabilities in Hitachi Energy TropOS 4th Gen Products (8DBD000214)

  • Vendor’s primary advisory (PDF/CSAF) with technical specifics, impact analysis, and the official remediation path for TropOS devices used in energy and industrial networks.

EV charger security ISO 15118 TropOS

How This Impacts Regular Users and Organizations

Even if you don’t run a power plant, you’re still connected to this world. Here’s how:

Everyday Life Impact

  • EV chargers in parking lots could be hijacked or disabled
  • Smart manufacturing downtime affects supply chains and product availability
  • Energy grid networks targeted = outages, higher costs, or worse

Business Impact

  • Unpatched ICS = regulatory fines, lawsuits, loss of public trust
  • Insurance carriers are now denying claims after “preventable cyber events”
  • Attackers don’t need physical access anymore, just outdated firmware

If you’re a:

RoleAction You Should Take
IT AdminScan networks for TropOS devices, confirm firmware
Facility ManagerAsk vendor if your chargers follow ISO 15118-20
EV Fleet OperatorVerify encryption, require certificate validation
ExecutiveRequest a written ICS risk assessment from your team

Relevant Source (NIST): Cybersecurity Framework Profile for Electric Vehicle Extreme Fast Charging Infrastructure

  • Provides a national-level, risk-based approach to securing EV charging systems, mapping practical controls to real-world threats and impacts on drivers and operators.

Relevant Source (GAO): Cyber Insurance: Action Needed to Assess Potential Federal Response to Catastrophic Cyber Incidents

  • Explains how cyber incidents affecting critical infrastructure can outstrip coverage, highlights exclusions and limits that lead to denied or reduced claims, and outlines implications for organizational risk management.

Immediate Actions: Secure EV Charging and ICS Now

  1. Ask vendors for proof of patching
  2. Require network isolation for anything controlling physical systems
  3. Stop assuming VPN = safe
  4. Create a “no internet browsing” policy for ICS equipment
  5. Report unusual behavior to CISA if suspected

Simple Reminder:

Anything that interfaces with the physical world deserves the same protection as a hazardous device. Use strict access control with continuous monitoring and tested fail safes. Do not treat operational technology like a casual website or a normal app.

Close EV Charging and ICS Security Gaps Today

These advisories aren’t fear-mongering. They are grounded in published research, assigned CVEs, and repeatable proof-of-concepts. EV infrastructure and industrial wireless tech keep rolling out faster than policies, training, and patch cycles. That growing gap becomes the attacker’s runway, where small misconfigurations and old firmware turn into outages, safety risks, and brand damage.

If you control any EV charging, ICS, or industrial network tech, act now. Run a documented audit, patch to the latest supported versions, and require written proof of compliance from every vendor. Segment networks, lock down remote access, and track remediation with clear owners and dates. The threat is real and the fixes are available, which makes inaction the only unacceptable risk.

Where JENI Fits In: Smart Security Starts at the Endpoint

Industrial systems don’t fail because of one giant mistake. They fail because of a chain of small ones: an unpatched device here, a reused password there, a forgotten laptop plugged into a control network. That’s where JENI comes in.

extend the life of your computer with jeni

JENI isn’t an ICS firewall or a network appliance. We handle the layer most organizations overlook: the endpoints people actually touch every day, admin workstations, diagnostics laptops, engineering PCs, and field devices that quietly become the foothold for bigger attacks.

How JENI Helps Reduce ICS Risk

  • Cleans and stabilizes Windows and macOS systems used to configure ICS networks
  • Removes junk, temp files, and corrupted data that slow down critical tooling
  • Detects and repairs system-level issues before they turn into attack vectors
  • Eliminates leftover credentials, logs, and cached data attackers love to harvest
  • No background processes, no data harvesting, no subscriptions, ever

Why it matters here:

Every TropOS patch, every EV charger firmware upload, every risk assessment starts from a computer. If that machine is unstable, outdated, or infected, it becomes the first point of failure, not the firewall.

  • Lightweight (1.16 MB on Windows, ~5.6 MB on Mac)
  • One license per device, lifetime use
  • 5–7× cheaper than bloated “security suite” cleaners
  • Zero telemetry, zero cloud tracking, zero ads

Your ICS network is only as clean as the device you use to manage it. If you can’t trust the laptop you plug into the charger, switch, or controller, you can’t trust the system at all.

Published on November 2, 2025 at 8:50 AM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.