Weaponizing Firmware, Cyberwarfare and Battery Management Systems: Ethical and Anticipated Ethical Issues

Authors

  • Richard Wilson Towson University
  • Noah Donnelly Towson University

DOI:

https://doi.org/10.34190/eccws.25.1.4860

Keywords:

Cyber-kinetic warfare, Battery Management Systems (BMS), Firmware weaponization, Anticipatory Technology Ethics (ATE), Dual-use technology, Thermal runaway, BootROM vulnerabilities, IoT security.

Abstract

As the Internet of Things (IoT), which is made up of “smart” devices, expands, in the cyber security space issues arise because cyber security which has traditionally focused on data privacy and service availability. However, a critical and under-analyzed threat vector lies in the weaponization of firmware to inflict kinetic physical damage on battery powered devices and battery management systems. This research analyzes the technical reality of manipulating Battery Management Systems (BMS) in civilian devices. By overriding safety protocols and de-throttling thermal limits, attackers can induce thermal runaway in lithium-ion batteries. This process effectively converts smartphones, laptops, and electric vehicles into incendiary devices. There is a reason why BMS security matters: The BMS directly governs safety limits; malicious interference could lead to device failure and fire risk, or grid instability when scaled. Modern connected devices increase the “attack surface” for cyber warfare via telematics, mobile apps, cloud APIs, and service diagnostics. Key risk categories (without operational details) include but are not limited to: Supply chain and tampering with components/firmware, insecure third‑party libraries. There are issues related to Firmware/boot including unsigned updates, insecure bootloaders. With communications (Comms) there are weak or missing authentication on CAN or diagnostic interfaces; replay or spoofing risks. Issues with applications include Cloud/app weak API/auth controls, insecure mobile app backends. There are also Safety/security co‑engineering gaps when functional safety (e.g., ISO 26262) and cybersecurity (e.g., ISO 21434) are not jointly considered. This paper explores the specific firmware vulnerabilities that allow for voltage manipulation and the bypass of hardware cut-offs for devices requiring batteries. Beyond the technical mechanics of batteries, we examine the ethical and legal implications of this "dual use" technology. This is where consumer electronics can be remotely triggered to cause fires or explosions. We argue that the potential for physical harm necessitates a reclassification of firmware vulnerabilities in power regulation modules, moving them from standard cybersecurity concerns to issues of public safety and kinetic warfare. This analysis will conclude with an ethical and anticipated ethical analysis of BootROM code when it is used in support of battery powered devices in cyberwarfare.

 

Author Biography

Richard Wilson, Towson University

Richard L. Wilson is a Professor in Philosophy at Towson University in Towson, MD. Teaching Ethics in the Philosophy and Computer and Information Sciences departments and Senior Research Fellow in the Hoffberger Center for Professional Ethics at the University of Baltimore. Professor Wilson specializes in Applied Ethics teaching a wide variety of Applied Ethics Classes.

Downloads

Published

2026-06-15