Research Library / Case Studies /

Automotive (Electric Vehicles)

Automotive Startup Finds Critical Vulnerabilities in EV With Payatu's Automotive Security Testing

A single unlocked ADB shell let testers break out of an electric scooter's dashboard straight into raw Android underneath. Payatu's automotive security team found unencrypted CAN Bus traffic that let them inject packets and seize control of the scooter's turn signals, even while the vehicle was in riding mode, before this high-performance EV startup scaled up for market.
IoT/Automotive Security Testing, Firmware Security Assessment, Hardware Security Assessment, Wireless (Bluetooth) Security Testing, CAN Bus Security Testing

At a glance

INDUSTRY

Automotive (Electric Vehicles)

CLIENT PROFILE

An electric mobility startup building high-performance electric scooters

SERVICES

IoT/Automotive Security Testing, Firmware Security Assessment, Hardware Security Assessment, Wireless (Bluetooth) Security Testing, CAN Bus Security Testing

ENGAGEMENT

End-to-end automotive product security assessment ahead of scale-up

key Numbers

15

Vulnerabilities Identified

12

Critical Severity Issues

4

High Severity Issues

Key Takeaways

  • Client – An electric mobility startup that designs, manufactures, and sells high-performance electric scooters.

  • Problem – The company needed its scooter's dashboard, firmware, hardware, in-vehicle network, and wireless connectivity tested before the product's security posture could be trusted at scale.

  • What Payatu did – Payatu's automotive security team ran firmware, hardware, Android dashboard, wireless (Bluetooth), and CAN Bus assessments, uncovering critical vulnerabilities

  • Outcome – Payatu handed the client a prioritized remediation plan covering ADB access controls, patching, encrypted storage, and CAN Bus monitoring.

the challenge

Why the client called us in

The client is an electric mobility startup with a scooter already on the market, offering fast dashboard interactions and a seamless ride experience. As the company grew, it wanted to be sure the product's hardware and software could hold up against real attackers before scaling further. It brought in Payatu to
assess the dashboard, firmware, hardware, in-vehicle network, and wireless
communication of the vehicle.

  • Test the scooter's dashboard, firmware, and hardware for exploitable
    weaknesses
  • Assess the CAN Bus network and Bluetooth connectivity for exposure
  • Get a clear, prioritized path to improve the product's security posture

scope of engagement

What was in scope

  1. Firmware & Hardware of the dashboard
  2. The in-vehicle network (CAN Bus)
  3. Wireless communication (Bluetooth) with the associated app

Our Approach

How Payatu ran the engagement

01

Firmware testing
Payatu inspected the kernel, bootloader, and architecture, extracted firmware and hardcoded credentials, analyzed custom binaries, and tested the firmware update, encryption, and secure boot validation mechanisms.

02

Hardware testing
The team mapped the board's controllers and memory chips, located debug ports such as UART, JTAG, and SWD, extracted and reflashed memory, and sniffed communication over the SPI/I2C bus.

03

Android dashboard testing
Payatu attempted authentication bypass, gained debug access, installed custom applications, rooted the device, and reverse engineered the Android applications running on the dashboard.

04

Wireless (Bluetooth) testing
The team identified and sniffed BLE communication, tested for replay, relay, and MiTM attacks, fuzzed characters, and verified Wi- Fi encryption and data exfiltration risks.

05

CAN Bus (network) testing
Payatu sniffed data packets from exposed bus endpoints, ran replay, spoofing, and fuzzing attacks on the CAN nodes, reversed CAN Bus packets, and tested UDS packet injection.

Key findings

What we found

CRITICAL
Escape to System via ADB
The ADB shell was accessible to a normal user, letting them run shell commands to escape the EV dashboard interface into core Android settings.
CRITICAL
Outdated, Unpatched Android Version
The dashboard ran an outdated Android build with no recent security patches, making remote exploitation possible.
HIGH
Unencrypted CAN Bus Enabling DoS and Spoofing
The vehicle's CAN Bus network was unencrypted, allowing packet injection attacks that could trigger denial of service or spoof signal indicator data.
HIGH
Dashboard Logs Exposed in Cleartext
Application logs on the dashboard exposed a JWT token and a Google Maps API key in cleartext, both readable by any application on the device.
HIGH
I2C Memory Extraction of Odometer Data
The I2C EEPROM storing odometer data could be dumped, modified, and reflashed by an attacker.

the outcome

Results and Impact

Despite limited access to the vehicle's internal E/E components and a crunched timeline, Payatu delivered a full picture of the scooter's security posture across firmware, hardware, dashboard, wireless, and network layers, along with prioritized fixes for each finding.

  • Identified 9 vulnerabilities across critical, high, and low severity

  • Flagged the ADB and outdated Android issues that gave the most direct path to compromise

  • Recommended CAN Bus encryption, a bus guardian, and CAN Bus IDS to stop packet injection attacks

  • Delivered bootloader lock-down and log access restrictions to close the remaining gaps

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment