Zero-day vulnerabilities are flaws the vendor has not found or patched, so no CVE feed lists them. TrustDyne cannot predict them. It can flag code that would make a memory-corruption bug easy to exploit.
By the time a CVE appears in the National Vulnerability Database (NVD), attackers may already have an exploit. A scan that only matches known CVEs says nothing about flaws nobody has reported yet.
TrustDyne reads the ELF binaries in a firmware image and flags vendor executables that import unsafe C functions such as strcpy, sprintf, gets or system. It then checks each binary for NX, PIE and stack canary protection. A binary with unsafe imports that lacks NX or PIE is rated HIGH instead of MEDIUM, because a buffer overflow in it is easier to exploit. The scan proves the import. It does not trace whether attacker input reaches the call, and the report says so.