Resumen:
The research field of vehicle cybersecurity has experienced a significant growth in interest due to the attack surface that the information systems comprising a vehicle provides and the ever-expanding body of regulations that provide special focus on cybersecurity on vehicular systems. Of particular interest is the attack surface exposed by OBD dongles, wireless devices that connect to the vehicle’s diagnostic port, whose access to the vehicle’s CAN buses could potentially be exploited by adversaries. However, acquiring a vehicle for use in the security assessment of these devices may not be possible for the researcher. In this article, we propose a software tool, pwnobd, that assists in developing proof-of-concept attacks seeking to take advantage of the found vulnerabilities, alongside an architecture for a research and demonstration platform that provides a testbed for vulnerability analysis and penetration testing for attacks towards these devices. A small battery of tests is then performed on several diagnostic devices using this platform, along with a focused study on one such device, proving the potential benefit of such platform for security researchers.

Resumen divulgativo:
Este artículo presenta pwnobd, una herramienta de software y banco de pruebas para evaluar vulnerabilidades en dongles OBD, que exponen los buses CAN del vehículo a posibles ataques. Permite desarrollar pruebas de concepto de ataques sin necesidad de un coche real, apoyando la investigación en seguridad.
Palabras Clave: Cybersecurity, car hacking, on-board diagnostics, embedded device, Bluetooth.
Índice de impacto JCR-JIF y cuartil WoS: 4,200 - Q2 (2025)
Referencia DOI:
https://doi.org/10.1109/ACCESS.2025.3589867
Publicado en papel: 2025.
Publicado on-line: Julio 2025.
Cita:
R. Gesteira-Miñarro, I. Gutiérrez, R. Palacios, G. López, "pwnobd: Offensive Cybersecurity Toolkit for Vulnerability Analysis and Penetration Testing of OBD-II Devices", IEEE Access, Vol. 13, pp. 126925 - 126934, 2025. [Online: Julio 2025] doi: 10.1109/ACCESS.2025.3589867