LIVE DEMO — Real TrustDyne scan of IoTGoat, OWASP's deliberately-vulnerable OpenWrt IoT firmware image. Real findings, real SBOM, real platform.

Security Evidence Pack

IoTGoatx86.img.gz · Scanned 21 Jun 2026 · OWASP IoT test firmware · TrustDyne Platform

Risk Score

94/100

CRITICAL RISK

Total Findings

14

4 critical · 8 high

Frameworks Failed

11/11

UK PSTI, EU CRA, ISO 27001 + 8 more

Financial Exposure

£1.7B

UK PSTI + EU CRA, 10K-unit fleet

SBOM: 25 of 248 real components shown · full inventory available in the platform

high

TrustDyne-001

EU CRA Annex I §1(a)

dnsmasq-dhcpv6 2.73-1

DNS cache poisoning vulnerability due to missing DNSSEC validation allows attackers to redirect firmware update checks and critical service lookups to malicious servers, enabling supply chain compromise.

CVSS 7.4

critical

TrustDyne-002

UK PSTI Sch.1 §1(1)(a)

miniupnpd 2.1-1

Unauthenticated UPnP port forwarding allows remote attackers to open arbitrary firewall ports and expose internal services (SSH, HTTP admin panel) to the internet without credentials via crafted SSDP packets.

CVSS 9.1

high

TrustDyne-003

ISO 27001 A.9.4.1

netifd 2018-11-19

UCI configuration parser lacks input sanitization, enabling authenticated attackers to inject shell commands through malicious network interface definitions, achieving root code execution.

CVSS 8.8

high

TrustDyne-004

IEC 62443 SL-2

uhttpd 2018-11-28 / LuCI

Session cookies lack HttpOnly and Secure flags, enabling session hijacking through XSS attacks in LuCI modules; attackers can steal administrator sessions via injected JavaScript.

CVSS 8.1

medium

TrustDyne-005

ISO 27001 A.9.4.3

rpcd 2018-11-28

RPC daemon lacks granular per-method authorization, allowing any authenticated user to invoke privileged system configuration APIs intended for administrators.

CVSS 6.5

critical

TrustDyne-006

UNECE R155 Annex 5B

uclient-fetch / opkg

Package manager performs HTTP-based updates without enforcing cryptographic signature verification beyond the initial keyring check, enabling MITM attackers to inject malicious firmware packages during updates.

CVSS 9

high

TrustDyne-007

NIST IoT Baseline

Dropbear 2017.75-7.1

Outdated SSH implementation predates critical authentication-bypass and cryptographic-weakness patches from 2019+, exposing administrative access to brute-force and protocol-downgrade attacks.

CVSS 7.5

medium

TrustDyne-008

IEC 62443 SL-1

firewall 2018-08-13 / iptables 1.6.2

Firewall package predates netfilter connection-tracking vulnerabilities (CVE-2019-11479 class), enabling attackers to bypass firewall rules via TCP SACK manipulation and fragment-reassembly attacks.

CVSS 6.8

high

CVE-2021-22555

CISA KEVEU CRA Annex I §1(a)

linux-kernel 4.14.95

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS via heap memory corruption through user name space.

CVSS 7.8

high

CVE-2024-1086

CISA KEVEU CRA Annex I §1(a)

linux-kernel 4.14.95

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation via a double-free when NF_DROP is issued with a drop error resembling NF_ACCEPT.

CVSS 7.8

high

CVE-2019-13272

EU CRA Annex I §1(a)

linux-kernel 4.14.95

ptrace_link in kernel/ptrace.c mishandles the recording of credentials of a process creating a ptrace relationship, allowing local users to obtain root access via certain parent/child process scenarios.

CVSS 7.8

high

CVE-2022-0492

EU CRA Annex I §1(a)

linux-kernel 4.14.95

A vulnerability in the Linux kernel's cgroup_release_agent_write (kernel/cgroup/cgroup-v1.c) allows the cgroups v1 release_agent feature to escalate privileges and bypass namespace isolation under certain circumstances.

CVSS 7

critical

CVE-2018-1000517

EU CRA Annex I §1(a)

busybox 1.28.4

BusyBox wget prior to a 2018 fix contains a buffer overflow vulnerability resulting in heap buffer overflow, exploitable via network connectivity.

No CVSS published

critical

CVE-2022-48174

EU CRA Annex I §1(a)

busybox 1.28.4

A stack overflow vulnerability in ash.c (busybox before 1.35) can be executed from command to arbitrary code execution in IoT/connected-vehicle deployment contexts.

No CVSS published

Ready to scan your own product?

Get a real Security Evidence Pack on your firmware or mobile app. First assessment free — SBOM, CVEs, remediation scripts, and full compliance mapping in one PDF.

Talk to Sales