logo

Study: Serious Web Security Flaws Rampant on Embedded Devices

ID: d8bfd5d8-877f-5e1a-9ace-da38a6f4aea3

STIX ID: report--d8bfd5d8-877f-5e1a-9ace-da38a6f4aea3

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2015-11-16

Date Updated: 2026-05-06

Author: Paul Roberts

...
...

A large-scale academic study emulating 246 embedded-device firmware images found that 185 (75%) contained high-impact web-interface vulnerabilities — totaling 9,271 issues — including command injection, XSS, CSRF, and credential/configuration exposures. The report highlights systemic problems (few firmwares enabling HTTPS, insecure default services like Telnet/FTP/RTSP, leftover manufacturing/testing modules) and vendor-specific examples (Netgear devices exposing configuration and credentials), stressing a broad attack surface across routers, CCTV and other IoT devices though it does not document confirmed active exploitation campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.