Man-in-the-Middle Vulnerability in Electric Vehicle Charging Protocols by IEC
CVE-2025-12357
Key Information:
- Status
- Vendor
- CVE Published:
- 31 October 2025
What is CVE-2025-12357?
This vulnerability allows attackers to exploit the Signal Level Attenuation Characterization (SLAC) protocol by sending spoofed measurements. By doing so, they can execute a man-in-the-middle attack between electric vehicles and ISO 15118-2 compliant chargers. The threat primarily arises from the possibility of wireless exploitation within close proximity, utilizing electromagnetic induction techniques. This could jeopardize the integrity of the data exchanged during charging sessions and potentially compromise the charging process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EV Car Chargers Part 15118-2 Network and Application Protocol Requirements
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
