XPeng P7i

From Wiki-IoT


Classification

XPeng P7i
Classification
Grade A
Calculator version 1
Classification date 2025-10-05
Information
Name XPeng P7i
Brand by Parent XPeng by XPeng Motors
Generation P7i
Model(s) Pro, Max, Wing Edition
Release date 2023-03-10
Type/Category Car
Website [1]
Status In sale
More
Dimensions 4888 x 1896 x 1450 mm
Mass ~1960 - 2170 kg
Operating system Xmart OS
Companion App XPeng App
CPU
GPU
Memory
Storage
Battery
Power
Charging
Display
Camera
Sound
Connectivity
Device
Criterion Value Proof(s) Comment
Known hardware tampering None [2] Complex integrated vehicle system where unauthorized physical tampering is extremely difficult and would be immediately detectable. No public reports of supply chain tampering.
Known vulnerabilities Rare [3] XPeng runs a dedicated security response center and bug bounty program. Vulnerabilities are addressed via mandatory Over-the-Air (OTA) updates.
Prior attacks None [4] No publicly documented, widespread security breaches have successfully compromised the XPeng vehicle platform.
Updatability Very common [5] A core feature (XOTA). The vehicle receives frequent and comprehensive OTA updates for the Xmart OS infotainment system and the XNGP advanced driving system.
Category score 2
System
Criterion Value Proof(s) Comment
Authentication with other systems Full [6] The vehicle maintains a persistent, secure connection to the XPeng cloud for remote control, vehicle diagnostics, and data-driven services.
Communications Encrypted with up-to-date encryption [7] All data communication between the vehicle, the cloud, and the companion app is protected by end-to-end encryption using industry-standard protocols.
Storage Encrypted with up-to-date encryption [8] Sensitive user data, including biometric information and driving data, is encrypted at rest both on the vehicle's internal storage and in the cloud.
Category score 1
User Authentication
Criterion Value Proof(s) Comment
Account management Full [9] An XPeng account is mandatory for all smart features. The system supports multiple driver profiles with personalized settings.
Authentication Secure [10] Supports multiple authentication methods: Phone as a Key (PaaK via Bluetooth/NFC/UWB), NFC card, facial recognition for driver profile login, and a PIN for sensitive vehicle settings.
Brute-force protection Exist [11] The in-vehicle system locks out after multiple incorrect PIN attempts. The cloud account has standard server-side brute-force protection.
Event logging Access event logged [12] The vehicle maintains comprehensive diagnostic and access logs. The cloud service logs all account access events for security auditing.
Passwords Require change after setup with complexity requirements [13] The required XPeng account enforces password complexity. An in-vehicle PIN for sensitive operations must be set by the user.
Category score 1
Grade A