
POV: you demo a vulnerability on stage in 2019, release a full exploitation tool (V2GInjector), present it at conferences and then get silent for some years... ...and in 2025 it finally gets a CVE because someone else reported it to CISA 💀 At least they credited us with JC Delaunay and @Karion_. Thanks CISA 🤝 CVE-2025-12357 — SLAC MitM on ISO 15118-2 EV charging. CVSS 8.3. AKA "the HPGP standard is broken by design, we told you so." https://www.cve.org/CVERecord?id=CVE-2025-12357
Post summary
The passage announces CVE-2025-12357, a MitM vulnerability in ISO 15118-2 EV charging, noting a previously demonstrated tool V2GInjector and a CVSS score of 8.3, but it offers no active exploitation or patch information.

