Research Library / Case Studies /

Automotive & Telematics (IoT)

Bridging Security: Pentesting an Automotive ECU

A global telematics company asked whether its vehicle-tracking ECU could survive a real attacker before launch. Payatu's team glitched the microcontroller, decrypted the firmware, and used an exposed MQTT broker to reach the client's production server.
Hardware Security Assessment, Firmware Security Assessment, BLE Security Testing, MQTT / IoT Protocol Assessment

At a glance

INDUSTRY

Automotive & Telematics (IoT)

CLIENT PROFILE

A global telematics company building ECUs and vehicle trackers

SERVICES

Hardware Security Assessment, Firmware Security Assessment, BLE Security Testing, MQTT / IoT Protocol Assessment

ENGAGEMENT

Black-box · three identical units for lab testing

key Numbers

3

Findings Identified

1

Critical Finding

4

Security Domains Assessed

Key Takeaways

  • Client – a global telematics company that designs Electronic Control Units (ECUs) and vehicle trackers for real-time vehicle health and location monitoring.

  • Problem – needed to validate the device's hardware, firmware, and wireless protocols against real-world attack techniques before market launch.

  • What Payatu did – ran a black-box hardware, firmware, BLE, and MQTT security assessment, including fault injection, JTAG/UART exploitation, and firmware decryption.

  • Outcome – found a critical MQTT misconfiguration that let testers reach the client's production server and extract unencrypted firmware and customer data, and delivered a prioritized remediation roadmap.

the challenge

Why the client called us in

Before taking the device to market, the client needed to know whether its ECU could withstand real-world attacks against its hardware, firmware, and wireless protocols. The scope covered the full attack surface: physical debug interfaces, encrypted firmware, Bluetooth Low Energy pairing, and the MQTT channel connecting the device to the cloud.

  • Validate hardware resilience against physical and fault-injection attacks
  • Decrypt and review firmware for embedded secrets and logic flaws
  • Assess BLE pairing and MQTT communication for unauthorized access

scope of engagement

What was in scope

  1. Hardware assessment
  2. Firmware assessment
  3. Radio protocol assessment (BLE)
  4. IoT protocol analysis (MQTT)

Our Approach

How Payatu ran the engagement

01

Hardware Assessment
Conducted at the Payatu lab using three identical units. Testing progressed from external interface reconnaissance and CAN/USB fuzzing to UART/JTAG debug access, power-glitching to bypass readout protection, and extraction of encrypted firmware from external flash.

02

Firmware Assessment
Extracted firmware was decrypted and analyzed for hardcoded secrets, insecure configurations, and logic flaws using the access obtained during hardware testing.

03

BLE Security Testing
Assessed the Realtek BLE 5.0 stack for exposure prior to pairing, tested known CVEs against the chipset, and executed enumeration and denial-of-service attacks against the pairing mechanism.

04

MQTT / IoT Protocol Assessment
Identified the device's MQTT broker through BLE traffic analysis, then tested for unauthenticated access, wildcard topic enumeration, and unauthorized data publication.

Key findings

What we found

CRITICAL
Insecure ecosystem interfaces
An exposed MQTT endpoint and credentials embedded in the firmware, hosted on an HTTP server, allowed testers to reach the client's production server and extract unencrypted firmware and customer data.
Insufficient privacy protection
BLE characteristics could be written to without proper passkey authentication.
Lack of physical hardening
An open SWD port on the Realtek BLE SoC had no authentication, exposing a physical debug interface.

the outcome

Results and Impact

Payatu's assessment gave the client a clear, prioritised remediation path before the device reached market, closing hardware, firmware, and protocol-level gaps that could have exposed customer data and production systems.

‍

  • Critical MQTT and firmware exposure identified before launch

  • Hardware debug interfaces secured against physical attack

  • BLE pairing hardened against unauthorized writes

  • Production server and customer data protected from unauthorized access

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment