Research Library / Case Studies /

Solar & Battery Energy Systems

Enhancing the Security Posture for Portable Energy Solutions

One of the largest solar and battery system providers asked Payatu to break its Portable Energy System before customers could. Testers extracted firmware from three separate PCBs, exposed a hardcoded root certificate, and crashed the BLE service remotely.
Hardware Security Assessment, Firmware Security Assessment, MQTT Protocol Security Assessment, BLE & Wi-Fi Radio Security Testing, Android Application Security Testing

At a glance

INDUSTRY

Solar & Battery Energy Systems

CLIENT PROFILE

One of the largest developers and providers of solar and battery systems

SERVICES

Hardware Security Assessment, Firmware Security Assessment, MQTT Protocol Security Assessment, BLE & Wi-Fi Radio Security Testing, Android Application Security Testing

ENGAGEMENT

White-box · PES device, firmware, and companion Android app

key Numbers

5

Security Domains Assessed

35

Findings Identified Across the PES Ecosystem

Key Takeaways

  • Client – one of the largest developers and providers of solar and battery systems, seeking to harden its Portable Energy System (PES) before wider customer rollout.

  • Problem – the PES device and its companion Android application had never been through a full-stack security assessment covering hardware, firmware, wireless, and application layers together.

  • What Payatu did – ran a black-box hardware, firmware, BLE, and MQTT security assessment, including fault injection, JTAG/UART exploitation, and firmware decryption.

  • Outcome – identified 35 findings including a hardcoded root certificate, unauthenticated MQTT topics, and remote BLE denial-of-service, then delivered fixes that physically and logically hardened the device.

the challenge

Why the client called us in

As solar and battery technology scales to meet growing demand, product quality now includes security. The client wanted its Portable Energy System hardened at every layer before customers relied on it, and asked Payatu to assess the device end to end rather than one component at a time.

  • Assess PES hardware, firmware, and radio protocols together, not in isolation
  • Validate MQTT communication between the device and backend
  • Test the companion Android application for the same class of risk as the device itself

scope of engagement

What was in scope

  1. PES firmware analysis
  2. PES hardware pentesting
  3. MQTT protocol implementation review
  4. PES radio pentesting (BLE and Wi-Fi)
  5. Android application security assessment

Our Approach

How Payatu ran the engagement

01

Hardware Assessment
Working from a stripped, battery-free unit, the team accessed UART and JTAG debug ports to capture boot logs, extract firmware, and pull data from external flash across all three onboard PCBs (BMU, SCU, and Gateway).

02

Firmware Analysis
Statically reverse-engineered the extracted ELF binaries in Ghidra for hardcoded secrets and memory corruption, then validated findings dynamically using the SCU board's exposed JTAG interface.

05

Wireless Assessment
Unauthenticated and authenticated testing of wireless protocols, encryption, and access controls.

04

MQTT Protocol Review
Assessed the device's MQTT broker communication for authentication, topic access control, and encryption in transit.

05

Android Application Testing
Ran static and dynamic analysis on the companion APK, covering reverse engineering, client-side protections, local data storage, and API-level access control.

Key findings

What we found

CRITICAL
BLE URL injection
A writable BLE handle let an attacker inject and overwrite a URL value used by the device over Bluetooth Low Energy.
HIGH
Exposed hardware debug and storage interfaces
An active SWD port on the STM32 controller allowed firmware extraction and re-flashing, while the ESP32's QSPI flash and the EEPROM chip, both reachable via the UART shell, could be read, written and patched without encryption.
HIGH
Remote BLE denial-of-service
A weakness in the BLE stack's Link Layer and L2CAP handling let an attacker crash the BLE service, force a remote device restart, trigger an on-device error message, or de- authenticate the connection, all without authentication.

the outcome

Results and Impact

Payatu's assessment moved the PES device from an unhardened prototype to a product ready for scaled customer rollout, closing gaps across hardware, firmware, radio, and application layers before launch.

‍

  • Hardware debug interfaces physically hardened against extraction

  • Firmware secrets and certificates no longer exposed in plaintext

  • BLE and Wi-Fi communication secured against enumeration and DoS

  • Android application hardened with SSL pinning and secure data storage

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment