Apart from what he points out in the article ("The PIC client is susceptible to a MitM (Man In The Middle) attack because it does not verify if the public key sent by a server is from a trusted party")
1. Weird encryption which seems to be XORing the plaintext against the same encrypted IV?
2. Using random padding instead of PKCS5 or similar?
3. Using memcmp instead of CRYPTO_memcmp or similar?