Description
BMW ZGW CANHacker is a CAN analysis and transmission tool designed to access vehicle networks through the BMW ZGW (Central Gateway).
Instead of connecting a CAN interface directly to individual bus wiring, the software communicates through the vehicle gateway using an ENET connection. It can be used for CAN traffic analysis, logging, testing and transmission of custom CAN frames.
Main functions
CAN / LIN / FlexRay access
The ZGW acts as the central gateway between different vehicle communication networks. ZGW CANHacker provides access through this gateway, allowing supported BMW CAN, LIN and FlexRay networks to be reached without making a direct physical connection to each individual bus.
For normal use, an ENET diagnostic connection is used between the PC and vehicle or test bench.
Receiver
The Receiver window can monitor live gateway traffic and display frames by bus, CAN ID, DLC and payload. The interface also provides filtering, logging and export functions, making it useful for investigating communication between BMW control units and identifying specific CAN messages.
Transmitter
The Transmitter allows individual or multiple CAN frames to be created and sent through the selected bus.
Transmission entries can include:
The included example TXL file demonstrates predefined CAN commands, while the CMT example provides CAN ID descriptions that can be displayed directly inside the program.
ZGWRemoteBridge
The package also includes ZGWRemoteBridge, a separate Java utility for working with a remote BMW connection.
It can bridge access to a remotely connected vehicle so that CAN traffic can be captured with ZGW CANHacker. Remote connections can be tunneled through solutions such as Hamachi or Radmin VPN.
Included files
Typical uses
[WARNING]
Transmitting arbitrary CAN messages can change vehicle states or interfere with control-unit communication. Test unfamiliar commands on a bench whenever possible and do not transmit frames unless you understand their function.
[/WARNING]
Video demonstration
A practical video demonstration is included below showing ZGW CANHacker operation, CAN traffic monitoring and message transmission.


Instead of connecting a CAN interface directly to individual bus wiring, the software communicates through the vehicle gateway using an ENET connection. It can be used for CAN traffic analysis, logging, testing and transmission of custom CAN frames.
Main functions
- CAN Receiver — capture and monitor CAN traffic passing through the BMW ZGW.
- CAN Transmitter — manually send CAN frames or transmit predefined command lists.
- Select available BMW CAN buses through the ZGW.
- Display CAN ID, DLC, payload, bus name and comments.
- Create periodic CAN messages with configurable transmission intervals.
- Single-shot or continuous transmission of selected frames.
- Load and save transmitter lists in .txl format.
- Use CAN ID description/comment files in .cmt format.
- Logging and offline analysis of captured traffic.
- Export captured data for further analysis.
CAN / LIN / FlexRay access
The ZGW acts as the central gateway between different vehicle communication networks. ZGW CANHacker provides access through this gateway, allowing supported BMW CAN, LIN and FlexRay networks to be reached without making a direct physical connection to each individual bus.
For normal use, an ENET diagnostic connection is used between the PC and vehicle or test bench.
Receiver
The Receiver window can monitor live gateway traffic and display frames by bus, CAN ID, DLC and payload. The interface also provides filtering, logging and export functions, making it useful for investigating communication between BMW control units and identifying specific CAN messages.
Transmitter
The Transmitter allows individual or multiple CAN frames to be created and sent through the selected bus.
Transmission entries can include:
- CAN ID and DLC
- CAN payload
- Transmission period
- Comments / signal descriptions
- Single-shot or repeated transmission
- Trigger-based operation
The included example TXL file demonstrates predefined CAN commands, while the CMT example provides CAN ID descriptions that can be displayed directly inside the program.
ZGWRemoteBridge
The package also includes ZGWRemoteBridge, a separate Java utility for working with a remote BMW connection.
It can bridge access to a remotely connected vehicle so that CAN traffic can be captured with ZGW CANHacker. Remote connections can be tunneled through solutions such as Hamachi or Radmin VPN.
Included files
- ZGW_CANHacker executable
- ZGWRemoteBridge
- CAN Activator TXL example
- CAN ID Description CMT example
- Instructions
- Receiver and Transmitter reference screenshots
Typical uses
- BMW CAN bus research and reverse engineering
- Test-bench work with BMW ECUs and head units
- Monitoring communication between control units
- Finding CAN IDs and payload changes
- Replaying or generating known CAN messages
- Testing functions when some modules are not present on a bench
- Remote CAN traffic analysis
[WARNING]
Transmitting arbitrary CAN messages can change vehicle states or interfere with control-unit communication. Test unfamiliar commands on a bench whenever possible and do not transmit frames unless you understand their function.
[/WARNING]
Video demonstration
A practical video demonstration is included below showing ZGW CANHacker operation, CAN traffic monitoring and message transmission.

