We find real exploit paths in shipped devices

Most IoT security assessments answer the wrong question. They measure coverage, count findings, or map controls — but never show how an attacker would actually compromise a device. Understand how your shipped device can be realistically compromised — and what that means for your business.

This audit is designed to answer one thing clearly:

Can this device be exploited in the real world, and how?

Who It's For

  • Hardware and IoT device vendors
  • Product security and firmware engineering leads
  • CTOs and technical founders
  • Teams shipping firmware-based products (consumer IoT, industrial systems, medical devices)

What We Deliver

  • Exploit chains or concrete abuse scenarios (where found).
  • Reproduction steps and proof-of-concepts (when feasible).
  • Executive risk summary focused on business impact.

Credibility

Bartosz Zglobicki — Independent Security Consultant

Background

  • 15 years in IT
  • 8 years software development (C / C++)
  • 7 years offensive security (pentesting and security research)
  • Former Security Consultant at F-Secure

Selected CVEs

  • CVE-2020-25782
  • CVE-2020-25783
  • CVE-2020-25784
  • CVE-2020-25785

Selected Research & Findings

  • Consumer IoT camera firmware

    • Identified multiple remotely reachable memory corruption flaws.
    • Demonstrated unauthenticated compromise path.
    • Resulted in CVE assignments.
  • Embedded Linux device (industrial class)

    • Unauthenticated privilege escalation via ssh login customization.
    • Persistent compromise demonstrated.
    • Client engagement (details withheld).

Contact

To discuss scope and suitability:
Initial contact by email only.