Automotive & Telematics (IoT)
Bridging Security: Pentesting an Automotive ECU
At a glance
INDUSTRY
Automotive & Telematics (IoT)
CLIENT PROFILE
A global telematics company building ECUs and vehicle trackers
SERVICES
Hardware Security Assessment, Firmware Security Assessment, BLE Security Testing, MQTT / IoT Protocol Assessment
ENGAGEMENT
Black-box · three identical units for lab testing

key Numbers
3
1
4
Key Takeaways
Client – a global telematics company that designs Electronic Control Units (ECUs) and vehicle trackers for real-time vehicle health and location monitoring.
Problem – needed to validate the device's hardware, firmware, and wireless protocols against real-world attack techniques before market launch.
What Payatu did – ran a black-box hardware, firmware, BLE, and MQTT security assessment, including fault injection, JTAG/UART exploitation, and firmware decryption.
Outcome – found a critical MQTT misconfiguration that let testers reach the client's production server and extract unencrypted firmware and customer data, and delivered a prioritized remediation roadmap.
the challenge
Why the client called us in
Before taking the device to market, the client needed to know whether its ECU could withstand real-world attacks against its hardware, firmware, and wireless protocols. The scope covered the full attack surface: physical debug interfaces, encrypted firmware, Bluetooth Low Energy pairing, and the MQTT channel connecting the device to the cloud.
- Validate hardware resilience against physical and fault-injection attacks
- Decrypt and review firmware for embedded secrets and logic flaws
- Assess BLE pairing and MQTT communication for unauthorized access
scope of engagement
What was in scope
- Hardware assessment
- Firmware assessment
- Radio protocol assessment (BLE)
- IoT protocol analysis (MQTT)
Our Approach
How Payatu ran the engagement
01
02
03
04
Key findings
What we found
the outcome
Results and Impact
Payatu's assessment gave the client a clear, prioritised remediation path before the device reached market, closing hardware, firmware, and protocol-level gaps that could have exposed customer data and production systems.
Critical MQTT and firmware exposure identified before launch
Hardware debug interfaces secured against physical attack
BLE pairing hardened against unauthorized writes
Production server and customer data protected from unauthorized access
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







