BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//talk//V3BXU
 8
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250926T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:OculaRCE: From Bluetooth to Contactor - Brendan Scarvell
DTSTART;TZID=Australia/Sydney:20260926T110000
DTEND;TZID=Australia/Sydney:20260926T115500
DTSTAMP:20260727T190121Z
UID:pretalx-bsides-canberra-2026-V3BXU8@cfp.bsidescbr.com.au
DESCRIPTION:A full-stack teardown of a commercial EV charger\, from defaul
 t credentials in the installation guide through to unauthenticated control
  of the AC power contactors.\n\nThis research covers multiple pre-auth RCE
  vulnerabilities including a Bluetooth attack requiring no network access\
 , an unauthenticated manufacturing test mode that bypasses every safety in
 terlock on the charger\, and a design flaw that puts all safety mechanisms
  in a single Linux process with no independent hardware verification.\n\nT
 he affected firmware platform is used by multiple resellers globally. A si
 ngle broadcast UDP packet can disable ground fault protection across an en
 tire fleet.
LOCATION:Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/V3BXU8/
END:VEVENT
END:VCALENDAR
