Automotive (Electric Vehicles)
Automotive Startup Finds Critical Vulnerabilities in EV With Payatu's Automotive Security Testing
At a glance
INDUSTRY
Automotive (Electric Vehicles)
CLIENT PROFILE
An electric mobility startup building high-performance electric scooters
SERVICES
IoT/Automotive Security Testing, Firmware Security Assessment, Hardware Security Assessment, Wireless (Bluetooth) Security Testing, CAN Bus Security Testing
ENGAGEMENT
End-to-end automotive product security assessment ahead of scale-up

key Numbers
15
12
4
Key Takeaways
Client – An electric mobility startup that designs, manufactures, and sells high-performance electric scooters.
Problem – The company needed its scooter's dashboard, firmware, hardware, in-vehicle network, and wireless connectivity tested before the product's security posture could be trusted at scale.
What Payatu did – Payatu's automotive security team ran firmware, hardware, Android dashboard, wireless (Bluetooth), and CAN Bus assessments, uncovering critical vulnerabilities
Outcome – Payatu handed the client a prioritized remediation plan covering ADB access controls, patching, encrypted storage, and CAN Bus monitoring.
the challenge
Why the client called us in
The client is an electric mobility startup with a scooter already on the market, offering fast dashboard interactions and a seamless ride experience. As the company grew, it wanted to be sure the product's hardware and software could hold up against real attackers before scaling further. It brought in Payatu to
assess the dashboard, firmware, hardware, in-vehicle network, and wireless
communication of the vehicle.
- Test the scooter's dashboard, firmware, and hardware for exploitable
weaknesses - Assess the CAN Bus network and Bluetooth connectivity for exposure
- Get a clear, prioritized path to improve the product's security posture
scope of engagement
What was in scope
- Firmware & Hardware of the dashboard
- The in-vehicle network (CAN Bus)
- Wireless communication (Bluetooth) with the associated app
Our Approach
How Payatu ran the engagement
01
02
03
04
05
Key findings
What we found
the outcome
Results and Impact
Despite limited access to the vehicle's internal E/E components and a crunched timeline, Payatu delivered a full picture of the scooter's security posture across firmware, hardware, dashboard, wireless, and network layers, along with prioritized fixes for each finding.
Identified 9 vulnerabilities across critical, high, and low severity
Flagged the ADB and outdated Android issues that gave the most direct path to compromise
Recommended CAN Bus encryption, a bus guardian, and CAN Bus IDS to stop packet injection attacks
Delivered bootloader lock-down and log access restrictions to close the remaining gaps
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







