Research Library / Case Studies /

IoT / Smart Building Automation

Infrastructure Assessment of an IoT Ecosystem

A German smart-building automation company asked Payatu to test its full IoT ecosystem, hardware, radio communication, web interface and source code, before rolling it out further. Testing found a single encryption key shared across every device in the ecosystem, meaning one compromised unit could expose the whole fleet.
Hardware Security Assessment, Web Application Security Testing, Secure Code Review

At a glance

INDUSTRY

IoT / Smart Building Automation

CLIENT PROFILE

A German company offering IoT-based smart building automation solutions

SERVICES

Hardware Security Assessment, Web Application Security Testing, Secure Code Review

ENGAGEMENT

Key Takeaways

  • Client – A German company offering IoT-based solutions that turn commercial facilities into smart buildings, with a broader automation range for the smart building space.

  • Problem – The client wanted its entire IoT ecosystem, hardware, cloud, web interface and source code, tested for security gaps before relying on it further.

  • What Payatu did – Ran a comprehensive assessment covering device hardware, the IEEE 802.15.4-based radio protocol, the web interface and a source code review.

  • Outcome – Found that devices could be booted from an SD card, that a single shared encryption key exposed the entire device fleet, and that access control gaps in the web interface exposed user data, all within a four-week engagement.

the challenge

Why the client called us in

The client builds IoT-based automation solutions that turn commercial facilities into smart buildings, with a portfolio spanning multiple automation use cases. To make its offerings robust and foolproof against intrusion, it wanted the whole ecosystem, hardware, cloud, web interface and code, tested for security gaps. The client brought in Payatu to run that assessment.

  • Test device hardware for physical and firmware-level weaknesses
  • Assess the radio protocol securing device-to-device communication
  • Review the web interface and source code for access control and credential handling gaps

‍
‍

‍

scope of engagement

What was in scope

  1. Hardware security assessment
  2. Web interface security assessment
  3. Source code review

Our Approach

How Payatu ran the engagement

01

Hardware Assessment
Found that the device could be successfully booted from an SD card, and mapped and assessed the IEEE 802.15.4-based radio protocol used for device communication.

02

Radio Communication Analysis
Decrypted the radio communication and extracted the encryption key from the hardware, then confirmed the same key was reused across every device in the ecosystem.

03

Web Interface Testing
Assessed the web application's access control mechanism, finding it allowed collection of connected users' information, including personal data, and modification of other users' credentials.

04

Source Code Review
Reviewed the source code and found hardcoded credentials in multiple places, including MQTT credentials and license keys.

Key findings

What we found

Hardware Boot Security
The device could be booted from an SD card, giving an intruder a path to control the device.
Shared Radio Encryption Key
The encryption key securing radio communication was extracted from the hardware and found to be common across every device in the ecosystem, so compromising one device could expose sensitive data and compromise all other devices and gateways.
Web Access Control
The application's access control was improperly implemented, allowing collection of all connected users' information, including personal data, and modification of other users' credentials.
Hardcoded Credentials
MQTT credentials and license keys were hardcoded in multiple places in the source code.

the outcome

Results and Impact

Payatu's four-week assessment let the client protect user-sensitive information before a leak could cause fraud or financial loss to end users, and close the loopholes that put its IoT system's intellectual property at risk.

‍

  • Shared encryption key across the device fleet identified before it could be exploited at scale

  • Web interface access control gaps exposing user data closed

  • Hardcoded MQTT credentials and license keys removed from source code

  • Full ecosystem, hardware, radio, web and code, assessed within four weeks

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment