Shravan Singh Rathore

Shravan Singh Rathore

Senior Cybersecurity Engineer @ L&T Technology Services

About

Passionate Hardware Security Researcher | IoT & Embedded Systems Expert | Cybersecurity Innovator | ISO/SAE 21434 & IEC 62443-4-2 Compliance Expert Driven by curiosity and refined through hands-on discovery, my journey in cybersecurity has led to impactful work across the global tech landscape. I specialize in uncovering and responsibly disclosing vulnerabilities in smart devices and embedded systems—where hardware and software intersect and security gaps often emerge. Over time, I’ve conducted deep research across major IoT ecosystems—helping shape vendor patch cycles and improve global standards. My work has strengthened product security for brands like Panasonic, TP-Link, Philips, Xiaomi, Honeywell, Tinxy, and Dahua, earning recognition through CVE publications, CERT acknowledgments, and coverage in ZeeNews, CyberNews, and MoneyControl. ⸻ Highlighted CVEs & Recognition: • Panasonic (CVE-2025-1073): Firmware integrity bypass via UART • TP-Link Tapo H200 & C500 (CVE-2025-3442, CVE-2025-1099): Info disclosure in smart cameras • Philips Lighting (CVE-2024-9991): Insecure firmware execution in smart lighting • Tinxy (CVE-2025-2189, CVE-2024-12094): Ecosystem and Android app vulnerabilities • Halls of Fame: Honored by Xiaomi, Honeywell, Panasonic, and Philips • CERT Recognition: Acknowledged by CERT-In and Japan CERT ⸻ Expertise & Impact: My core strength lies in chip-off forensics, UART/SPI/JTAG exploitation, firmware reverse engineering, and SDR-based radio attacks. I’ve built and led specialized training programs, including sessions at Black Hat Asia, and helped vendors strengthen their security pipelines through testing, validation, and remediation. ⸻ Tools I Rely On: • Firmware Analysis: Ghidra, IDA Pro, binwalk • Hardware Hacking: JTAGulator, OpenOCD • Wireless & SDR: HackRF One, Universal Radio Hacker • Penetration Testing: ADB, Frida, Burp Suite • Protocols: CAN (J1939), BLE, UART, SPI ⸻ Mission-Driven & Community-Focused: Beyond the lab, I’m dedicated to knowledge-sharing—mentoring students in robotics, Arduino, and embedded electronics, while running workshops and university sessions to spread awareness on hardware security and ethical hacking. ⸻ From dissecting firmware to educating the next generation of security minds, my mission is clear: protect the connected world, one vulnerability at a time. Let’s build a safer, smarter future—together.

Country

India

City

Mumbai

Industry

Security & Investigations

Skill

U.S. Health Insurance Portability and Accountability Act (HIPAA), ICS, ISO 13485, ISO 27001, ISO 26262, ISO 9001, IEC 30141, Vulnerability Assessment, Debugging, Cybersecurity, Internet of Things (IoT), IoT Security, Healthcare Security, Automotive Assessment, System on a Chip (SoC), Threat Modeling, Threat & Vulnerability Management, Mobile pentesting, Apk pentesting, Cybersecurity Tools

Experience

L&T Technology Services

Senior Cybersecurity Engineer

L&T Technology Services

LinkedIn
2024-11 - Present · 1 yr 11 mos

Mumbai

Vanderlande – OPC UA Server/Client & OT Network Pentest Aligned with ISO/IEC 62443 (Security for Industrial Automation and Control Systems) 🔹 OPC UA Server/Client – Tested authentication, authorization, session/endpoint security, and method/variable access control. 🔹 Siemens Scalance Switch – Assessed network segmentation, ACLs, and management interface for exploitation paths. 🔹 PLC ↔ SCADA Communication – Validated secure channel usage, replay protection, and command integrity across industrial devices. 🔹 Mitigation Recommendations – Delivered actionable fixes for hardened OPC UA policies, network zoning, and secure endpoint configuration. Parker GVI Gen2 Inverter – Attack Surface & Red Team Assessment Aligned with ISO/SAE 21434 (Road Vehicles – Cybersecurity Engineering) 🔹 JTAG Debug Interface – Evaluated direct memory access and firmware extraction; tested access control enforcement. 🔹 CAN Bus (UDS Protocol) – Fuzzed UDS to uncover unsafe diagnostics and access bypasses. 🔹 Firmware – Reverse-engineered for insecure boot flow, hardcoded credentials, and privilege escalation. 🔹 Chip-Level Extraction – Performed chip-off techniques to examine secure storage mechanisms. 🔹 Side-Channel Attack Surface – Assessed power analysis feasibility on cryptographic operations in lab conditions. 🔹 Secure Boot & Logging Validation – Audited boot sequence, anti-rollback mechanisms, and log integrity. Danfoss FC302 VFD – External Attack Surface Analysis Aligned with ISO/IEC 62443 (Security for Industrial Automation and Control Systems) 🔹 Ethernet Interface – Evaluated TCP/IP stack, unauthenticated services, and remote configuration endpoints. 🔹 RS-485 / RS-232 – Tested serial command injection, session weaknesses, and physical-layer access abuse. 🔹 PROFINET – Assessed industrial Ethernet for spoofing, replay attacks, and denial-of-service conditions. 🔹 Firmware – Reverse-engineered binaries to detect missing code signing and insecure update mechanisms.

Kavach IoT Security

Founder

Kavach IoT Security

LinkedIn
2024-7 - Present · 2 yrs 3 mos

Mumbai Metropolitan Region

🔹 Recognitions & Hall of Fame Mentions • Xiaomi – Hall of Fame • Honeywell – Hall of Fame • Panasonic – Hall of Fame • Philips Lighting (Signify) – Hall of Fame • Dahua – Official recognition for vulnerability disclosures • Digisol – Multiple vulnerabilities reported and acknowledged • Syrotech – Multiple vulnerabilities reported • ZKTeco – Multiple vulnerabilities reported • CERT-In (India) – CVE recognition and coordinated public disclosure • Japan CERT – Recognition and CVE publication support • Media Features: Vulnerability research covered by ZeeNews, CyberNews, MoneyControl • RedFox Security Advisory: Full advisory published based on Smart Home IoT and embedded vulnerability research 🔹 Published CVEs • CVE-2025-1073 – Panasonic: Improper enforcement of firmware integrity via UART • CVE-2025-2189 – Tinxy Ecosystem: Information disclosure vulnerability • CVE-2025-3442 – TP-Link Tapo H200: Information disclosure in smart hub • CVE-2025-1099 – TP-Link Tapo C500: Security flaws in smart surveillance camera • CVE-2024-9991 – Philips Lighting Ecosystem (Signify): Firmware security bypass • CVE-2024-10523 – TP-Link Tapo H100 Hub: Vulnerability in device-cloud interaction • CVE-2024-12094 – Tinxy Android App: Mobile application data exposure 🔹 Additional Achievements • Multiple IoT products tested and responsibly disclosed to vendors • Collaborated with vendors to validate vulnerabilities and assist with patch development • Contributions to national and international CVE databases • Disclosure pipeline ongoing – several devices under responsible disclosure and research

Redfox Cybersecurity

Cyber Security Engineer

Redfox Cybersecurity

LinkedIn
2023-12 - 2024-11 · 1 yr

Mumbai, Maharashtra, India

🔹Hardware cybersecurity specialist with expertise in vulnerability assessments. 🔹Skilled in reverse engineering hardware devices. 🔹Secured multiple CVEs. 🔹Experienced in identifying vulnerabilities in embedded devices like routers, smart lacks, etc. 🔹 Prepared hardware security training course for Black Hat Asia 2025, covering chip-off analysis of various IoT devices and an overview of their vulnerabilities. 🔹CVE-2024-25343 🔹CVE-2024- 28325 🔹CVE-2024- 28326 🔹CVE-2024- 28327 🔹CVE-2024- 28328 🔹CVE-2024- 2257 🔹CVE-2024- 4231 🔹CVE-2024- 4232 🔹CVE-2024- 36787 🔹CVE-2024- 36788 🔹CVE-2024- 36789 🔹CVE-2024- 36790 🔹CVE-2024- 36792 🔹CVE-2024- 36795 🔹CVE-2024- 33373 🔹CVE-2024- 33374 🔹CVE-2024- 33375 🔹CVE-2024- 34377 🔹CVE-2024- 41684 🔹CVE-2024- 41685 🔹CVE-2024- 41686 🔹CVE-2024- 41687 🔹CVE-2024- 41688 🔹CVE-2024- 41689 🔹CVE-2024- 41690 🔹CVE-2024- 41691 🔹CVE-2024- 41692

CoE CNDS Lab, VJTI

Postgraduate Researcher (Cybersecurity)

CoE CNDS Lab, VJTI

2022-7 - 2023-12 · 1 yr 6 mos

Mumbai, Maharashtra, India

🔹Replay attack on : 🔸Car key but it had rolling keys enabled 🔸Successful replay attack on the drone radio controller 🔸Wireless bell 🔹Explored and conducted research in IoT Security, Hardware Hacking, Drone Forensics, Firmware Analysis and SDR Exploitation. 🔹Vulnerability analysis and penetration testing of Smart plugs and Wifi routers. 🔹Hands on experience with tools like JTAGulator, Bus Pirate, Logic Analyzer, Burp Suite, Metasploit, Kali Linux, Attify OS, Firmadyne, Firmwalker, FAT, HackRF One, Universal Radio HAcker, etc.

Mechatron Robotics

Robotics Engineer

Mechatron Robotics

LinkedIn
2022-7 - 2023-2 · 8 mos

Mumbai, Maharashtra, India

🔹 STEM Education Advocacy: Promoted STEM Education methods for a deep understanding of Robotics and emerging tech among students. 🔹Commitment to Quality: Key role in upholding the commitment to high-quality education for student growth. 🔹Project-Based Learning: Facilitated practical application of theoretical knowledge through projects. 🔹Personalized Training: Tailored learning experiences to meet individual student needs. 🔹Diverse Skill Set: Cultivated a broad skill set, covering both technical and non-technical skills. 🔹Multifaceted Subjects: Taught diverse subjects including Robotics, Electronics, and Arduino to school and college students. 🔹Concept Simplification: Made complex concepts in electronics and programming accessible to students. 🔹Engagement with Institutions: Actively engaged with schools and colleges through workshops and seminars. 🔹Training Material Development: Contributed to creating comprehensive training materials for students. 🔹Project Guidance: Guided students in practical project development. 🔹Research and Innovation: Actively involved in research and innovation, fostering creative robotics projects. 🔹Competition Promotion: Organized Robotics competitions to fuel healthy student competition. 🔹High-Level Competition Prep: Supported students aiming for excellence in competitions, including at the IIT level.

NVIDIA

Quality Analyst

NVIDIA

LinkedIn
2021-11 - 2023-1 · 1 yr 3 mos

Pune, Maharashtra, India

🔹Lidar Linker. 🔹Image analysis. 🔹Labelling & assigning attributes. 🔹Quality analysis of labelled images.

NVIDIA

Process Executive (Payroll Randstad)

NVIDIA

LinkedIn
2021-9 - 2021-11 · 3 mos

Pune, Maharashtra, India

🔹Labelling 🔹Quality on Labelling 🔹Data annotation, Closely working with Image annotation. 🔹Projects: 🔸Polyline 🔸Polygon 🔸2D Labelling 🔸3D labelling 🔸Lidar Linker 🔸Scene labelling 🔸Curation Creating 2D 3D bounding box Lidar marking knows the overview of video labelling and text labelling.

Robokart.com

Research And Development Engineer

Robokart.com

LinkedIn
2019-6 - 2020-10 · 1 yr 5 mos

Borivali, Maharashtra, India

🔹Workshops were conducted across India for: 🔸National Robotics Championship 🏆 🔸ATL ( Atal Training Lab ) 🔸Lab Setup 🔹Overall Lab Consist of Various: 🔸Microcontroller 🔸Drones 🔸3D Printer 🔸Various Sensors 🔸 Embedded and IoT projects 🔹Developing Strong Expertise in the Field of Embedded Systems, microcontrollers, Robotics, Firmware/Programming around 8-bit/32-bit microcontrollers and IoT-based sensors. 🔹To nurture Innovation and Creativity at K12 School Level students by mentoring and helping them to develop Innovative Embedded Projects with the use of technology in the delivery of curricula through a variety of instructional methods (hardware, software, and Internet resources in support of learning). 🔹Organizes, develops and coordinates special STEM Engineering and Technology based events/activities. 🔹Always willing to innovate newer Technologies like the Internet of Things (IoT), Machine Learning, Virtual Reality (VR), Augmented Reality (AR), and Advanced Processor Programming.

Doordarshan Kendra

Broadcaster Engineering Training

Doordarshan Kendra

LinkedIn
2018-12 - 2018-12 · 1 mo

Mumbai, Maharashtra, India

🔹Training and Exposure: I have received comprehensive training and hands-on exposure to various aspects of television program operation and maintenance. 🔹Diverse Sections: My training covers a wide range of sections within television production, including transmission, production, and post-production. 🔹Specific Areas: The specific areas of expertise I've gained include Studio operations, Studio Lighting, Earth Station operations, High Power Transmitters, and Field Production Units. 🔹Comprehensive Knowledge: I possess a deep understanding of the technical and operational intricacies associated with these television program sections. 🔹Hands-On Experience: I have practical experience in operating and maintaining equipment and systems related to these television program sections, ensuring seamless broadcasting and production processes.

Education

Veermata Jijabai Technological Institute (VJTI)

Veermata Jijabai Technological Institute (VJTI)

LinkedIn

Electronic and Telecommunication

2021-6 - 2023-8 · 2 yrs 3 mos
Atharva College of Engineering

Atharva College of Engineering

LinkedIn

Electrical, Electronics and Communications Engineering

2015 - 2019 · 4 yrs

Shravan Singh Rathore's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.