As home EV chargers get smarter, they also inherit new attack surfaces. Understanding how power line communication works and where it can go wrong can help homeowners make better security decisions before convenience turns into security incidents. For many homeowners, a wallbox feels like a simple appliance you can just mount, connect, charge the car with, and move on. But modern EV charging extends beyond mere electricity, as many chargers now combine cloud connectivity, firmware updates, mobile companion apps, remote management and, in some cases, even standardized communication between the vehicle and charger over power line communication (PLC). Although the added intelligence brings much more convenience, it also expands the attack surface. Standards used in EV charging, especially ISO 15118, rely on HomePlug Green PHY to carry data between the vehicle and charging equipment over the charging connection itself. As researchers have pointed out, several weaknesses affect EV charging communications, including eavesdropping and man-in-the-middle (MiTM) attacks, under certain conditions. While this doesn’t mean every home charger can be hacked from the street, it does mean homeowners should stop seeing their wallboxes as mere “power devices.” In reality, these devices are better categorized as IoT endpoints with physical charging roles. In plain language, PLC in EV charging allows the car and charger to negotiate charging parameters and, in some cases, support advanced features such as Plug and Charge. The issue is that researchers have found design and implementation flaws around this communication process. A notable CISA advisory from late 2025 warned that manipulating the SLAC (Signal Level Attenuation Characterization) pairing process in ISO 15118-2 could facilitate an MiTM attack, potentially even wirelessly at close range via electromagnetic induction. This vulnerability is tracked as CVE-2025-12357 and is marked as medium on the severity scale. Earlier academic work also showed that CCS charging