To be more exact, a battery with ID 0xFFFF (hhm, not sure if it was 16 or 32 bit) enables service mode on older PSPs. This ID is stored on a serial EEPROM. Incidentally, you could just disconnect the data pin of the EEPROM. I don't remember if it was I2C (in which case the pin was SDA) or SPI (MISO).
So it wasn't exactly a security vulnerability, more like a failed attempt at security by obscurity.
So it wasn't exactly a security vulnerability, more like a failed attempt at security by obscurity.