Security1 distinct publisher3 min readUpdated
Pen Test Partners says the battery maker declined to fix exposed older installs and did not act when the UK regulator asked. On 9 April 2026 it entered administration.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Pen Test Partners says the battery maker declined to fix exposed older installs and did not act when the UK regulator asked. On 9 April 2026 it entered administration.
GivEnergy Ltd entered administration on 9 April 2026, two days after filing a notice of intention to appoint administrators on 7 April 2026 [1][2][3]. According to Pen Test Partners, which found multiple vulnerabilities in the company's home battery systems in late 2024, that collapse arrives with older installations still exposed and no clear remediation plan communicated to customers [4][5].
The technical story is unglamorous, which is the point. PTP reports that earlier batteries ran a Wi-Fi access point as well as acting as a client, and that some shipped with the pre-shared key set to 12345678 [6][7]. On its own units the key was not default, but the broadcast SSIDs matched the serial numbers printed on the gateway labels, in the form WK12345G67 [8]. Section 8 of GivEnergy's 2024 Wi-Fi dongle installer guide recommended using the inverter serial number as the password [9]. PTP notes the serial is also broadcast in the SSID, and that a query against the public wardriving dataset wigle.net by SSID pattern returns the GPS location of these batteries alongside the key [10][11].
Getting onto the access point was not the end state. A port scan of the gateway found HTTP on 80, Telnet on 23, an API on 8899 and an exposed Modbus TCP interface [12]. PTP's summary is that the deployment created a backdoor onto customer networks and also allowed the battery to be made inoperative [13].
The vendor response is the part worth reading twice. GivEnergy updated installer guidance for newer deployments but, per PTP, refused to address the issue for existing customers [5][14]. PTP also says the company failed to act when the Office for Product Safety and Standards contacted it about a breach of the UK PSTI Act [15]. Then it went insolvent [1].
Most third-party risk programmes have a box for supplier failure, and it is filed under continuity: who answers the phone, who honours the warranty, where do we source replacements. PTP, a customer itself, says the collapse leaves customers wondering exactly that about support and warranty [16]. But the residue here is not a service gap. It is a physical device sitting on a home or small-office LAN, with a documented weak-key pattern, a Telnet listener and a Modbus interface, and now no party with either the code signing keys or the commercial incentive to ship a fix. Vendor viability is usually scored as a financial control. It is a patch-availability control.
The regulatory gap is the same shape. PSTI-style IoT rules work by pointing an enforcement agency at a manufacturer, importer or distributor. That model assumes the target continues to exist. Roughly sixteen months passed between PTP's late-2024 findings and the administration, including a regulator contact that PTP says produced no action [4][1][15][17]. An enforcement notice against a company in administration is not a firmware update.
What to watch: whether the administrators, or any buyer of the assets, accept the outstanding security obligation along with the brand; whether OPSS says anything about how it handles PSTI cases when the duty-holder dissolves; and whether PTP's own self-help guide for non-technical owners remains the only remediation route on offer [18]. For operators, the near-term question is narrower: whether any of this kit is on a network you are responsible for, and whether it is segmented away from everything else.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
GivEnergy Ltd filed a notice of intention to appoint administrators on 7 April 2026.
In late 2024, Pen Test Partners found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers' home networks, disrupt battery operation, and potentially violate UK product security regulations.
Earlier GivEnergy batteries had a Wi-Fi access point in addition to needing to act as a Wi-Fi client, and the access point was not reconfigured by clients during setup.
Earlier GivEnergy batteries had the Wi-Fi pre-shared key set to 12345678.
A Wi-Fi survey by Pen Test Partners showed SSIDs in the form WK12345G67 that correlated with the serial numbers on the labels on the side of the battery gateways; on PTP's own units the PSK was not the default.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party technical work, single publisher, third-party conduct unverified
The technical core is specific and independently checkable in principle: SSID format correlated with gateway serials, a citable vendor installer manual (WiFi Dongle Guide 2024, section 8), a named public-dataset query, and named ports and services including Telnet with documented defaults on an HF-A21-SMT module. All of it, however, comes from one publisher testing its own units, with no CVE identifiers, no affected-version or serial ranges, and no corroboration for the claims about the vendor's refusal to remediate or its non-response to OPSS.
One disclosed install plus public-dataset hits, no population scale
Real-world footprint is demonstrated but unsized. The researcher documents its own office deployment of All In One 6.0 units and reports that wigle.net queries surface other gateways by location, which shows the pattern is not confined to a lab. Nothing in the supplied material gives numbers of affected installs, share of older versus newer deployments, or any evidence of exploitation in the wild.
Severity framing outruns the sized, corroborated evidence
The framing - a backdoor with nobody left to patch it, a vendor that refused to fix and ignored the regulator - is broader than what the single source demonstrates. The device-level findings are credible and specific, but the number of still-exposed installs is unknown, no exploitation is shown, and the two most damaging claims (refusal to remediate, unanswered OPSS request) are unverified assertions against a company now in administration and unable to respond. Modestly overstated rather than dramatically so, because the underlying technical detail is genuinely concrete and the insolvency is a dated, checkable event.
Sole narrator is a commercial security vendor and an affected customer
Pen Test Partners is a penetration-testing firm publishing research that markets its capability, and it is simultaneously a GivEnergy customer with unresolved support and warranty exposure, and the author of the remediation guide it points readers to. It discloses the customer relationship, which is a mitigating factor, but it is the only voice in the cluster and the accused party is in administration and cannot answer.
Technical findings credible, conduct and scale claims unresolved
Confidence is moderate. The device-level findings are internally consistent, methodologically described and partly verifiable against vendor documentation, so the core security story is likely sound. Confidence is held down by the single-publisher structure, the researcher's dual commercial and customer interest, the absence of vendor, administrator or regulator input, and the complete lack of scale data on how many legacy installs remain exposed.
build
GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim1 distinct publisher
security
CDN Tsunami: the protocol translation you pay for is the amplifier1 distinct publisher
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026