Pwn2Own Automotive 2026: Cybersecurity for our charging solutions

Phoenix Contact was once again represented at the renowned Pwn2Own Automotive 2026 security competition in Tokyo this year. For the third time in a row, the AC charging controller CHARX control modular was nominated as an official target device – a clear sign of the technical significance and security quality that our products are accorded in the international research community.

2026 was also a special year: for the first time, Robin Pape, Product & Solution Security Expert (PSSE), accompanied the competition on site. He observed the attempts against our controller, analyzed attack chains, and ensured clean, responsible documentation throughout the coordinated disclosure process for the further development of our cybersecurity processes at Phoenix Contact E-Mobility.

Why Pwn2Own is different from traditional security tests

Pwn2Own differs significantly from traditional security tests.

In contrast to a regular penetration test, in which individual teams work with a clearly defined task, here several highly specialized security researcher teams compete against each other, each using completely different methods and approaches to compromise our charging controller.

In addition, the competition rules provide strong incentives to search as deeply as possible for unknown attack vectors: “The Pwn2Own rules, which award less prize money for vulnerabilities found multiple times , incentivize security researchers to explore different attack vectors and ‘dig deep’ in order to find vulnerabilities that may have been overlooked by other teams.”

This structure makes the Pwn2Own event one of the most valuable platforms worldwide for gaining new security-related insights for your own products.

High level of professionalism among security researchers

The live demonstrations in Tokyo impressively showed how precisely and carefully the research teams work. Many arrived with complete attack chains for several target devices. This shows that without intensive preparation, a spontaneous, targeted attack on the target devices in this year’s competition would not have been possible at all.

 

Robin sums up the professionalism of the event as follows: “I had the impression that the teams were all very well prepared. Most of them had exploits for multiple targets in their luggage. A lot of preparation time went into this. The findings were not random hits, but the result of highly professional work by talented and experienced security researchers.”

Lab mode instead of reality – and still extremely valuable

“The AC charging controller CHARX control modular was used in ‘lab mode’ at Pwn2Own. This means it was set up openly with direct access to all interfaces, which is very different from normal use in a charging station. The setup therefore does not correspond to the reality in the field. Certain features were deliberately activated in advance. These are disabled by default in normal operation and are actually only intended for configuration purposes.” – Robin Pape

This confirms that the requirements at Pwn2Own go beyond normal field conditions, but precisely for this reason provide extremely valuable insights for our Product & Solution Security Expert Robin Pape.

Positive feedback and new ideas from the community

The feedback on how vulnerabilities found in previous years were handled was particularly gratifying. Both the security researchers and Trend Micro praised Phoenix Contact’s professionalism, transparency, and responsiveness in this regard.

“We were able to take away many valuable suggestions that will be incorporated into the further improvement of the cybersecurity of our products – so that we are well equipped to deal with threats in the future.” – Robin Pape

Conclusion: A competition that makes us stronger

Participation in Pwn2Own Automotive 2026 once again confirms the value of collaboration with the global security community.

We gain early insight into potential vulnerabilities, continuously improve our security architecture, and strengthen the robustness of our products – long before threats become relevant in the field. The issues identified are incorporated into a structured analysis and solution process. In accordance with Phoenix Contact’s established cybersecurity processes, we will provide updates via the CERT@VDE platform.

We are grateful for the open exchange with the TrendAI Zero Day Initiative (ZDI) and the many strong market players who were also present. Special thanks go to the creativity and perseverance of security researchers from around the world. Together, we are able to stand up for safe mobility and continue to drive it forward.
One thing is also clear: our products are technically top-of-the-line. And we take every opportunity to improve them further.

FAQ

Frequently asked questions

Pwn2Own Automotive is an internationally recognized security competition in which security researchers attempt to attack connected vehicles, charging infrastructure, and automotive components in a targeted manner. The aim is to uncover previously unknown vulnerabilities in order to improve the cybersecurity of products at an early stage. The 2026 competition took place in Tokyo, Japan.

Phoenix Contact uses Pwn2Own Automotive to have its charging solutions tested under extremely demanding conditions. Several independent, highly specialized teams attack our charging controller – much more intensively than in a classic penetration test. This gives us early indications of possible vulnerabilities and allows us to continuously improve the security of our products and processes.

The charging controller is tested in what is known as lab mode: openly structured, with direct access to all interfaces. In addition, some functions are activated that are deactivated in regular charging station operation or are only used for configuration. The setup is therefore deliberately more stringent than real field conditions – but that is precisely why it provides particularly in-depth security-related insights.

Discover suitable products now

Here you will find a selection of relevant products – based on the topics and recommendations from our blog post.

Table of contents

Your personal contact person

For all queries regarding our components for electric vehicles. I will be happy to advise you on our charging inlets and our vehicle charging controller and look forward to receiving your call or email.

Robin Pape
Product & Solutions Security Expert

You might also be interested in

Person arbeitet an einer Ladeeinrichtung für Elektrofahrzeuge unter einem überdachten Ladepark mit Solarpanel-Dach. Links steht ein großer Lkw, rechts ein Pkw, und im Vordergrund ist eine CHARX-Ladesäule mit Kabel sichtbar.

CCS megawatt charging: New standards for the charging infrastructure of electric utility vehicles

The mobility of the future is being shaped now, including that of the commercial vehicle sector, where CCS megawatt charging[...]

Two men stand in front of an outdoor DC charging station. It bears the logo 'PHOENIX CONTACT' and contains electronic components, cables and circuits. One of the men points to a component inside while the other watches intently. Trees and a parking lot with cars can be seen in the background.

How can the charging process be optimally controlled?

The question of how a charging process can be optimally controlled is central to the charging infrastructure of electric vehicles.[...]

AC charging controller CHARX control moduular surrounded by illustrations of industrial processes and data management: worker with tools and clipboard, cloud symbol, laptop user with diagrams, two people at computers analyzing data. Other symbols show safety, gears and connectivity in front of an industrial cityscape with buildings and cars.

The perfect AC charging controller for operators, manufacturers and planners: What is important?

What does a software update cost you? Not in euros, but in time, nerves and trust. The charging controller is[...]

Mail

emobility@phoenixcontact.de

Send us an email. We will answer your request as soon as possible.

Phone

+49 5235 3-43890

We are at your disposal Mon – Thu from 7:30 a.m. – 4:00 p.m. and Fri from 7:30 a.m. – 3:00 p.m.