IoTGoatx86.img.gz · Scanned 21 Jun 2026 · OWASP IoT test firmware · TrustDyne Platform
Risk Score
94/100
CRITICAL RISK
Total Findings
14
4 critical · 8 high
Frameworks Failed
11/11
UK PSTI, EU CRA, ISO 27001 + 8 more
Financial Exposure
£1.7B
UK PSTI + EU CRA, 10K-unit fleet
SBOM: 25 of 248 real components shown · full inventory available in the platform
TrustDyne-001
EU CRA Annex I §1(a)dnsmasq-dhcpv6 2.73-1
DNS cache poisoning vulnerability due to missing DNSSEC validation allows attackers to redirect firmware update checks and critical service lookups to malicious servers, enabling supply chain compromise.
CVSS 7.4
TrustDyne-002
UK PSTI Sch.1 §1(1)(a)miniupnpd 2.1-1
Unauthenticated UPnP port forwarding allows remote attackers to open arbitrary firewall ports and expose internal services (SSH, HTTP admin panel) to the internet without credentials via crafted SSDP packets.
CVSS 9.1
TrustDyne-003
ISO 27001 A.9.4.1netifd 2018-11-19
UCI configuration parser lacks input sanitization, enabling authenticated attackers to inject shell commands through malicious network interface definitions, achieving root code execution.
CVSS 8.8
TrustDyne-004
IEC 62443 SL-2uhttpd 2018-11-28 / LuCI
Session cookies lack HttpOnly and Secure flags, enabling session hijacking through XSS attacks in LuCI modules; attackers can steal administrator sessions via injected JavaScript.
CVSS 8.1
TrustDyne-005
ISO 27001 A.9.4.3rpcd 2018-11-28
RPC daemon lacks granular per-method authorization, allowing any authenticated user to invoke privileged system configuration APIs intended for administrators.
CVSS 6.5
TrustDyne-006
UNECE R155 Annex 5Buclient-fetch / opkg
Package manager performs HTTP-based updates without enforcing cryptographic signature verification beyond the initial keyring check, enabling MITM attackers to inject malicious firmware packages during updates.
CVSS 9
TrustDyne-007
NIST IoT BaselineDropbear 2017.75-7.1
Outdated SSH implementation predates critical authentication-bypass and cryptographic-weakness patches from 2019+, exposing administrative access to brute-force and protocol-downgrade attacks.
CVSS 7.5
TrustDyne-008
IEC 62443 SL-1firewall 2018-08-13 / iptables 1.6.2
Firewall package predates netfilter connection-tracking vulnerabilities (CVE-2019-11479 class), enabling attackers to bypass firewall rules via TCP SACK manipulation and fragment-reassembly attacks.
CVSS 6.8
CVE-2021-22555
CISA KEVEU CRA Annex I §1(a)linux-kernel 4.14.95
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS via heap memory corruption through user name space.
CVSS 7.8
CVE-2024-1086
CISA KEVEU CRA Annex I §1(a)linux-kernel 4.14.95
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation via a double-free when NF_DROP is issued with a drop error resembling NF_ACCEPT.
CVSS 7.8
CVE-2019-13272
EU CRA Annex I §1(a)linux-kernel 4.14.95
ptrace_link in kernel/ptrace.c mishandles the recording of credentials of a process creating a ptrace relationship, allowing local users to obtain root access via certain parent/child process scenarios.
CVSS 7.8
CVE-2022-0492
EU CRA Annex I §1(a)linux-kernel 4.14.95
A vulnerability in the Linux kernel's cgroup_release_agent_write (kernel/cgroup/cgroup-v1.c) allows the cgroups v1 release_agent feature to escalate privileges and bypass namespace isolation under certain circumstances.
CVSS 7
CVE-2018-1000517
EU CRA Annex I §1(a)busybox 1.28.4
BusyBox wget prior to a 2018 fix contains a buffer overflow vulnerability resulting in heap buffer overflow, exploitable via network connectivity.
No CVSS published
CVE-2022-48174
EU CRA Annex I §1(a)busybox 1.28.4
A stack overflow vulnerability in ash.c (busybox before 1.35) can be executed from command to arbitrary code execution in IoT/connected-vehicle deployment contexts.
No CVSS published
Get a real Security Evidence Pack on your firmware or mobile app. First assessment free — SBOM, CVEs, remediation scripts, and full compliance mapping in one PDF.