Solar & Battery Energy Systems
Enhancing the Security Posture for Portable Energy Solutions
At a glance
INDUSTRY
Solar & Battery Energy Systems
CLIENT PROFILE
One of the largest developers and providers of solar and battery systems
SERVICES
Hardware Security Assessment, Firmware Security Assessment, MQTT Protocol Security Assessment, BLE & Wi-Fi Radio Security Testing, Android Application Security Testing
ENGAGEMENT
White-box · PES device, firmware, and companion Android app

key Numbers
5
35
Key Takeaways
Client – one of the largest developers and providers of solar and battery systems, seeking to harden its Portable Energy System (PES) before wider customer rollout.
Problem – the PES device and its companion Android application had never been through a full-stack security assessment covering hardware, firmware, wireless, and application layers together.
What Payatu did – ran a black-box hardware, firmware, BLE, and MQTT security assessment, including fault injection, JTAG/UART exploitation, and firmware decryption.
Outcome – identified 35 findings including a hardcoded root certificate, unauthenticated MQTT topics, and remote BLE denial-of-service, then delivered fixes that physically and logically hardened the device.
the challenge
Why the client called us in
As solar and battery technology scales to meet growing demand, product quality now includes security. The client wanted its Portable Energy System hardened at every layer before customers relied on it, and asked Payatu to assess the device end to end rather than one component at a time.
- Assess PES hardware, firmware, and radio protocols together, not in isolation
- Validate MQTT communication between the device and backend
- Test the companion Android application for the same class of risk as the device itself
scope of engagement
What was in scope
- PES firmware analysis
- PES hardware pentesting
- MQTT protocol implementation review
- PES radio pentesting (BLE and Wi-Fi)
- Android application security assessment
Our Approach
How Payatu ran the engagement
01
02
05
04
05
Key findings
What we found
the outcome
Results and Impact
Payatu's assessment moved the PES device from an unhardened prototype to a product ready for scaled customer rollout, closing gaps across hardware, firmware, radio, and application layers before launch.
Hardware debug interfaces physically hardened against extraction
Firmware secrets and certificates no longer exposed in plaintext
BLE and Wi-Fi communication secured against enumeration and DoS
Android application hardened with SSL pinning and secure data storage
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







