The EV charging industry has well-established security standards. OCPP provides clear guidelines for securing the communication channel between EV Chargers and the Charging Station Management System. While the industry has focused on securing the backend communication, the attack surface exposed through the CCS2 charging plug remains largely untested.
I was reading about CCS using PLC networking today, trying to find adapters that accept power via CCS and deliver it via ChaDemo (this involves a man-in-the-middle board, naturally).
But I would not have imagined that some company ships a product with SSH listening on an interface anyone can reach and root:root as the credentials.
I hope this is an exception, but also hope the security researchers test as many charging stations as they can.
You would be surprised.