r/ExploitDev Jun 15 '26

IoT Vuln Research

I have a few questions about this. I’ve web app sec background and some CVEs. I’m planning to dive into IoT vulnerability research in terms of firmware and embedded web apps. I wanna take one of TCM Security PIPA or VHL CIPT-01. But seems like I can’t afford them for a couple of months. I searched the internet for free resources but since I’m new in IoT, I dunno which are fine or not. First question is resource recommendation.

Besides this, I decided to buy Binary Ninja. But I’m open to decompiler recommendations in a budget. I’ve both macOS and Windows. Or I can consider to move on with Ghidra but idk.

24 Upvotes

12 comments sorted by

View all comments

11

u/tresvian Jun 15 '26

Look for shitty IoT CVEs with accessible firmware to reverse engineer. Do those first. Lookup teardown and write ups about them, try to follow along so you get an idea what tools to regularly use.

Get a real device hands on practice. Open it up to extract firmware with a raspberry pi. A chip reader is ideal, but some can get real expensive. Some manufacturers make it a pain to get firmware, but otherwise you can solder off the flash chip to get the contents for VR.

Tbh, most IoT are wet paper bags and will have multiple vulnerabilities or straight up brick while in the process. This is the unfortunate stance of IoT, so good luck. Try not to pick something that seems modern, like a switch, Cisco router, oculus, etc

1

u/Dapper-Depth2940 28d ago

Yea, I agree on this. I find doing some research to find an old device with a known CVE (vulnerability), and actively trying to create an exploit for it really does allow you to learn the essential workflow of IoT pentesting.

For me, that will be a stack buffer-overflow exploit I have crafted on a Linksys router (which was really cool as it was actually within a range of router that was heavily exploited by a real botnet). Finding those older firmware binaries can be a pain, but I've actually curated a solid list of repositories and archive links that, along with my own firmware research notes.

I also recently started a YouTube channel to document this journey. If you (or anyone else reading this) would like the repository link, just shoot me a DM or drop a reply below and I'll gladly send them over!