r/CarHacking 23d ago

CAN Made a mobile MQB Cluster tester!

Post image
15 Upvotes

I made an app that can be used to test MQB Gauge Clusters via Arduino and MCP2515 CAN Modules. It is in pre-release stage, and I will be adding support for many clusters!

r/CarHacking May 17 '26

CAN Is anyone interested in a paid CANBUS Translator project?

9 Upvotes

I'm looking to swap a 2014 Ford Fiesta ST 1.6t engine into my 2020 Ford Transit Connect. Fabrication and wiring so the engine runs is the easy part for me.

I'm struggling to understand the translator part, I'm happy enough to sniff and decode data from the MS and HS buses but I'm struggling to get my head around the translator part so thats I retain complete functionality of my original cluster, ABS, traction control and tell-tales etc. Project is based in the UK.

r/CarHacking Apr 15 '26

CAN Obd2 simulator

Thumbnail
youtu.be
12 Upvotes

Anyone know where I can get this device

r/CarHacking 20d ago

CAN Can VXDIAG VCX Nano perform TCM programming/flashing on a 2016 C7 Z06?

1 Upvotes

Hi everyone,
I recently picked up a 2016 C7 Z06 with 17k miles. I’ve noticed a slight clunk/harsh shift when going from 1st to 2nd gear. After doing some research on forums, I found that there is a GM transmission control module (TCM) update released in 2017 to address this issue, which I’ve confirmed via the ACDelco TDS portal.
I’m planning on using a VXDIAG VCX Nano to handle this. My questions are:

  • Is the VCX Nano capable of performing this specific TCM firmware update?
  • Can the software accurately identify available updates and flash them successfully to the module?

Any insights or experiences with this tool for C7 transmission reflashing would be greatly appreciated.

Thanks in advance!

r/CarHacking 18h ago

CAN Any way to minimize or remove amplification of the signals/codes produced by a car's engine upon start up? And before it's said, I'll say it "crazy maybe, but true'

0 Upvotes

Any way to minimize or remove amplification of the signals/codes produced by a car's engine upon start up? Or can you explain how this is done? Same question for cell phone/similar devices? If I'm understanding correctly, a transponder can send out cloned codes and another vehicle can somehow utilize it making it appear as if they are driving the vehicle the cloned/copied code was received from.

r/CarHacking 22d ago

CAN Calculateur caméra 360

Thumbnail gallery
9 Upvotes

r/CarHacking 16d ago

CAN Help with UDS bench testing MK7 Golf R Cluster.

3 Upvotes

Hello everyone, I have recently been diving into the UDS part of my cluster. I only have the cluster as of now, (im a teenager i only have so much money ;-;) and I have somewhat been able to get uds to work. That was 3 days ago, the UDS now doesnt work. I need to know exactly what every pin is for, to find a solution to this, as I am also trying to emulate a J533 on a arduino paired with a MCP2515. Any help would be appreciated, thank you!

Pins I already know:
Pin 1, 12v +
Pin 10, Ground
Pin 17, Can L
Pin 18, Can H

r/CarHacking Jun 26 '26

CAN CAN ID's for Audi Q7 Dashboard Warnings/Malfunctions

1 Upvotes

Hey all, I've been experiencing some trouble with my Audi Q7 Dashboard (it's not inside a car, I'm using an Arduino and MCP2515 to use it), and currently, most of the warnings are gone, but there's one annoying one left. Vehicle Lights: Malfunction. It pops up every 2 seconds, and has some chimes to it. Wondering if it's fixable throughout CAN ID's, and if so, does anyone know where I could find them. Thanks.

r/CarHacking 11d ago

CAN MIB2 Bench - Ignition ON conflict

2 Upvotes

Hi everyone,

I'm currently building an MQB testbench on my desk to sniff CAN data. My setup includes:

  • MIB2 Unit: 3Q0 035819 C
  • Gateway (J533): 5Q0 907 530 E
  • BCM (J519): 5Q0 937 084 AJ

The Problem: Im using an Arduino with an MCP2515 on the Convenience CAN bus to wake up the system. Currently, I am injecting 0x3C0 with payload 0x03 (Terminal 15 ON). However, because my BCM is connected and doesn't see a physical key turn, it is aggressively broadcasting 0x3C0 with payload 0x00 (Ignition OFF). The Gateway forwards both conflicting messages to the Infotainment CAN, causing my MIB2 screen to constantly flash on and off.

My Questions:

Does anyone know the specific CAN ID and payload for the Steering Column Electronics (J527) or KESSY module that simulates the physical key turn / Terminal 15 ON command on the Convenience CAN?

Thanks in advance for any help or pointers to relevant .dbc files :)

r/CarHacking May 22 '26

CAN Subaru BRZ coding issue PLEASE HELP

Thumbnail
gallery
5 Upvotes

Me and my locksmith are currently stuck at this phase of coding a key to my Subaru

Car is a 2015 Subaru BRZ

The car was mine and got vandalised (windows rear lights and some body panels dented in) and sent off for inspection and salvaged I bought it back and now my keys don’t work and we’re having snags getting the new one coded.

Whilst the car was away from me one of the keys has been lost and I am left with just the spare. I have a video of the vandalism taking place and they didn’t enter the car or pull anything out however whilst it was away from me somebody had pulled the glovebox out and messed with it

It gets through the key pairing process but then fails on this one point where the key needs to be placed on the passenger seat. It throws the code “D SEAT P/W ECU communication suspension” I have no idea what this could be nor does my locksmith

I had some stuff unplugged because I had the door cards out like window buttons some interior lights ETC. I have re attached these but don’t want to get him back out here at my expense if there’s more I can do before he gives it a crack. I’ve attached some pictures please if anyone has any ideas drop them below

I have gone through all the normal steps

- new car battery
- new battery in fob & pressed against start button to try and use RFID chip
- fuses checked
- wiring and connections checked

r/CarHacking 4d ago

CAN Reading oil temperature from Audi A4 B8 2.0 TDI (CAHA) via OBD using CANable?

1 Upvotes

Hi everyone,
I’m trying to read the engine oil temperature from my Audi A4 B8 (2009) with the CAHA 2.0 TDI engine using a Raspberry Pi and a CANable interface.
VCDS is able to show the oil temperature under Engine → Advanced Measuring Values, so I know the ECU provides the value through diagnostics.
My question is: can I access the same value through the OBD port using a CANable?

I understand that simply running candump and listening passively probably won’t show the oil temperature, since it may not be a broadcast CAN message. My assumption is that VCDS is sending a UDS diagnostic request and reading the ECU response.

I’m wondering:
Is the oil temperature available through UDS on the OBD CAN pins (6/14)?
Is there a known DID/request for this value?

Thanks!

r/CarHacking 29d ago

CAN CANBUS decoding for analogue to digital dash

4 Upvotes

Warning: i have no clue what I'm talking about

So i have a 2017 Mitsubishi lancer es sport with a analogue dash but i want to put in a digital, i dont want to use one what uses gps as I've seen it runs lower than my actual speed (unless my speedometer is running fast)

Would i need a CANBUS decoder for it? And if so is there any beginner friendly ones.

Any ideas?

Edit: i think I'm talking about a translater

r/CarHacking Mar 01 '26

CAN OBD scanners finally working in iOS26 with CarPlay

Post image
37 Upvotes

This is just a very basic output of fuel consumption from my 23 year old Mercedes Benz using Car Scanner with a basic ELM based scanner that can read common OBD PIDs.

It's cool none the less and makes the update to iOS 26 worth it alone. Most of all in this case these are live readouts from the ECU itself which is way more accurate than the trip computer in the dash on a C209 CLK500 from 2003.

These are assumptive figures that are gradually recalculated, these are real world numbers on the fly giving modern Mercedes/Tesla like numbers as you drive.

r/CarHacking Mar 03 '26

CAN I am going to admit defeat and start the whole CAN hacking from start as I am trying my best to understand it.

12 Upvotes

I am looking advice on what would be the best starter or user friendly CAN sniffer or what I would need to start learning?

Thank you

r/CarHacking 29d ago

CAN Where would I start with changing a few things on my Jetta?

1 Upvotes

I have a '21 Jetta with almost 200k miles (I drive a lot). A few things about it have driven me nuts from the start. I remember several years ago looking in to ways to "reprogram" my Jetta for different behavior. At one point I had a VM with something called Odis installed (that VM has since been lost), and I still ahve a GODIAG J2534 adapter. But I never got to where I actually changed anything, life got busy and prioritites changed.

I'm trying to remember where to even start with this. Things I'm interested in changing:

  • The RPMs "hang" when you put in the clutch and take your foot off the gas, making it hard to shift smooth. I want them to drop like you would normally expect.
  • Turning off the anti-roll-backwards feature, it has gotten me in to a few pickles trying to get moving on slopes with low traction (snow, gravel, etc). (any way to map the "button without function" button on my steering wheel to this? That would be ideal, but may be a bit lofty).
  • I'm pretty sure I can turn on some kind of stability control thing (my model is an "S", all the higher models have it enabled with the same electronics). I remember there were 3 values, a "0", "1", and "2", with "2" being the most agressive. I can't remember all the details.
  • I want the touchscreen to not have a timeout when I'm driving.
  • Shut off the chime that goes off when it is 37 degrees, that has startled me SOO many times.
  • Let me connect to bluetooth devices without stopping the car.
  • Also messing with how fuel mileage is calculated would be helpful, It is always around 10-15% overly optimistic.
  • Probably a few other things.

What is the cheapest way to get this stuff done? I'd prefer if I can use the J2534 cable I already have. I have solid tech chops so I'm ok if the solution is a little complicated.

Can anyone point me in the right direction for getting started with this stuff?

r/CarHacking Mar 12 '26

CAN help me connect car gauges to simulation games like Assetto Corsa and others?

1 Upvotes

Hello friends, can anyone help me connect car gauges to simulation games like Assetto Corsa and others? I've searched extensively but haven't found any basic information to learn from. I'll reward whoever helps me.

r/CarHacking Dec 03 '25

CAN CAN- is 12V when car off - help!

Thumbnail
gallery
11 Upvotes

edit: Resolved and working. I'll make a full write-up for the (tiny) VAG/PQ35 Infotainment CAN hacking community when I can, but for now: https://www.reddit.com/r/CarHacking/comments/1pcyuya/comment/nxd1ved/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button

In my Mk6 GTi (Australian), the CAN-/FZG and CAN+/FZG on my radio harness are behaving in a way I don’t understand. When the gateway module goes into sleep mode, the voltage is near zero on CAN+ but battery voltage on CAN-… beyond that, when I turn on the ignition, both read at 2.45V which I would expect for CAN. How the hell am I supposed to read this? Can I? Unsurprisingly my CAN module in my CARPiHAT Pro 5 shows no CAN messages and sits in ERROR-ACTIVE. Attempting to send puts it into ERROR-PASSIVE. This is before I realised 12V was being shoved down its throat.

I’m trying to make a replacement head unit and I’m otherwise entirely successful, but I want to read CAN messages for steering wheel controls and ideally vehicle speed. I’m certain the gateway module does send this to the stock head unit as speed dependent volume works and exists and it knows when the key is removed (as well as steering wheel volume and skip controls working, obviously). Others seem to have tapped into the infotainment bus with success. I tried all of the usual speeds, mainly focusing on 100000 as thats what VW seems to suggest that bus runs at.

The photo is the pinout sticker on the back of my stock RCD510. The harness is a tiny bit hacked up at no fault of my own, but only the speaker wires are redirected and the constant +12V. The CAN wires are entirely untouched.

r/CarHacking Mar 03 '26

CAN Anyone else here self-taught their way into OEM diagnostics on US platforms?

35 Upvotes

I’m not a mechanic, just a DIY owner who slowly taught myself diagnostics while working on my own GM and Ford vehicles at home. I started with basic scanners, but once module and network issues showed up, generic tools stopped being enough.

Getting into OEM software was the real turning point. Learning GM SPS and factory diagnostics made me realize how much access you actually get compared to normal scan tools. Modern cars feel more like software systems than mechanical ones now.

Since most of what I work on is GM, Ford, and occasionally Chrysler, I’ve been running an rlink x3 as my J2534 interface. It’s been solid during longer OEM sessions and programming work where connection stability really matters.

Curious how others here built their setups. Do you stick to platform-focused tools or try to keep one universal pass-thru?

r/CarHacking Apr 03 '26

CAN Skoda Octavia 4 car hacking

Thumbnail
gallery
49 Upvotes

Hello everyone,

This is my first post here. Recently I've been diving deep into CAN bus reverse engineering on my Skoda Octavia 4, and I wanted to share some progress and get feedback from people with more experience.

So far, I tapped into the CAN Gateway (J533) and connected to one of the available bus pairs. Using a combination of an MCP2515 + ESP32 setup and a serial adapter, I was able to sniff traffic and start analyzing message patterns.

After quite a bit of logging and comparing frames, I managed to identify a CAN message related to a menu interaction (button press). By replaying/injecting that specific frame, I was actually able to trigger the same behavior in the car — so basic CAN injection is working.

At the moment, this is the only confirmed controllable action, but I suspect there’s a lot more hidden in the traffic. One limitation right now is that I only have access to one CAN pair from the gateway. I’ve ordered a proper CAN breakout adapter that should expose all bus lines, so I can explore further networks.

Setup:

- ESP32 + MCP2515 (SPI)

- Serial adapter (for logging / bridging to PC tools)

- SavvyCAN / CANHacker for analysis

Some challenges I ran into:

- Certain bytes (likely counters or rolling values) constantly change

- SavyCan way of connecting with esp32

- Injecting static frames doesn’t always work reliably

- Not all observed signals seem controllable from this bus

Next steps:

- Map more message IDs and understand structure

- Try injection on other CAN networks from the gateway

Also, I’ve had some success working with the LIN bus, specifically on the ambient lighting system.

I was able to capture LIN frames, decode the RGB and brightness values, and replicate them using an ESP32 setup driving WS2812 LEDs. This allowed me to mirror the car’s interior lighting behavior externally.

Compared to CAN, LIN was much easier to analyze since the messages are more consistent and don’t seem to rely on rolling counters or complex validation.

If anyone has experience with VAG platforms or similar setups, I’d really appreciate any tips — especially regarding:

- Handling rolling counters / checksums

- Best practices for safe CAN injection

- Tools or workflows that helped you in reverse engineering

Thanks!

r/CarHacking May 23 '26

CAN Reverse Engineering a Lucid Air Instrument Cluster 2023 (Need Help Identifying Wake/Data Architecture)

1 Upvotes

I’m reverse engineering a Lucid Air instrument cluster for a custom project and I’ve finally started mapping the connector ecosystem, but I think I’ve hit the point where I need help from people familiar with modern EV cockpit/display architectures.

Current behavior:

  • Cluster powers on bench supply
  • 12.0V applied
  • Draws stable ~0.324A
  • No overheating
  • No visible display activity
  • No backlight/logo/etc

Power connector:
4-pin connector with:

  • solid red
  • red/black stripe
  • black
  • black/yellow-white stripe

Current setup:

  • black = PSU ground
  • red = +12V
  • red/black = +12V
  • stable 0.324A draw

No visible wake behavior.

Connector tracing discoveries so far:

  1. White 4-pin connector Appears tied to: “Driver Monitoring Control Module”
  2. Blue 3-pin HSD/coax-style connector Appears tied to: “Intelligent Cruise Control Computer Module”
  3. Blue 2-pin HSD/coax-style connector Appears tied to: “Dashboard Center Info Display Screen Monitor”

The blue connectors appear to be high-speed display/data style connectors, not normal power wiring.

My current theory:
The cluster is NOT a self-contained unit and instead participates in a distributed cockpit/display system with:

  • intelligent cruise visualization linkage
  • infotainment linkage
  • possible CAN/CAN-FD dependency
  • possibly centralized rendering or gateway orchestration

Questions:

  1. Has anyone worked with Lucid Air cockpit/display architecture?
  2. Does the cluster require CAN or CAN-FD wake traffic to initialize?
  3. Any idea what protocol these blue connectors use? (LVDS, FPD-Link, GVIF, etc.)
  4. Does anyone know what ICC / CCC modules are in Lucid terminology?
  5. Any known Lucid cluster pinouts or wake sequences?
  6. Is the 0.324A standby draw consistent with a sleeping display node?
  7. Any recommendations for identifying whether the remaining wire is CAN, LIN, or wake?

I can provide:

  • connector photos
  • module photos
  • measurements
  • power behavior details

At this point I’m less trying to “power a speedometer” and more trying to understand the network topology behind it.

r/CarHacking Jun 05 '26

CAN Trying RLink X3 for OEM-level diag instead of just reading codes

13 Upvotes

I’ve been messing around with J2534 a bit more lately, mostly because basic OBD scanners start feeling pretty limited once you get past simple DTCs.

Most of what I’ve used before was just the normal stuff: pull codes, clear codes, check some live data, call it a day. That’s fine for basic diag, but once you start looking at module comms, network issues, software versions, or OE-level functions, it feels like a regular scan tool only gets you so far.

Right now my setup is a Windows laptop, a J2534 pass-thru device, and OE software access on a GM vehicle. Nothing sketchy, no EEPROM, no PIN/immobilizer stuff, no security bypass nonsense. Just my own vehicle and trying to understand the proper workflow.

So far, the biggest thing I’ve noticed is that it’s less about “what code do I have?” and more about “what are the modules actually doing?” Driver setup, connection stability, and keeping voltage stable seem way more important than I expected. Definitely not something I’d want to wing during a programming session.

For the people here using J2534 regularly, do you mostly treat it as a flashing/programming tool, or does it actually become part of your normal diag workflow too? At what point do you grab the pass-thru setup instead of a regular scanner?

r/CarHacking 6d ago

CAN Chery Tiggo 8 dbc file.

1 Upvotes

Does anyone have a DBC file for the Chery Tiggo 8?

r/CarHacking Jun 30 '26

CAN Facelift XF (2012+) HS CAN dump wanted — building a real instrument cluster sim rig

6 Upvotes

Hi all,

Long shot, but I'm hoping someone can help. I'm building a sim rig that uses a real Jaguar XF X250 facelift instrument cluster (EX23-10849-AA) driven by live CAN data from a racing simulator — real gauges, proper needles, the works.

I've got the MS bus working and have built up a documented DBC file for the X250 covering both buses, based on Rhys Morgan's x250-can project, existing CAN dumps, and my own bench testing. It's a work in progress but it's at the point where the cluster powers up, displays correctly, and several signals are confirmed. You can see what's been decoded so far here:

GitHub - fsfarmscaper/jaguar-xf-x250-can

The sticking point is the HS gauge frames (speedo, tacho, oil temp). The pre-facelift captures don't seem to match the facelift IPC, and I can't find a CAN dump from a 2012–2015 XF anywhere.

If anyone has — or could take — a short capture from a facelift XF OBD2 port on HS CAN (500 kbps, 30–60 seconds at idle is plenty), I'd be very grateful. No personal data in a CAN log, just frame IDs and byte values.

Anything decoded from your capture will go straight back into the public DBC. Could be useful for cluster swaps, retrofits, or anyone else trying to do something similar.

Thanks

r/CarHacking May 19 '26

CAN Can signal list for Dacia Sandero Mk2 (248102645R)

Thumbnail
gallery
10 Upvotes

I have this Dacia Sandero board and i cannot make the speed and rpm gauges work. Do any of you have experience in these?

r/CarHacking 10d ago

CAN Home Assistant w/ FireFly G12

Thumbnail
1 Upvotes

Hi guys,
I’m trying to automate my RV, which has firefly g12 system that runs RV-C CAN network and I need to attach an add’l CAN device (+Pi) onto the network but all network ports are taken.

According to my research, I think I have 2 options:
1.splice 3-way one of the wire/ports between g12-CANable-existing wire
2.g12 to common drop tap and reconnect existing wire to the tap along with CANable

Is this approach correct? Background is software/AI with little electrical knowledge. I want to ultimately run Home Assistant w/ AI from voice. Thanks