We find real exploit paths in shipped devices
Most IoT security assessments answer the wrong question. They measure coverage, count
findings, or map controls — but never show how an attacker would actually compromise a
device. Understand how your shipped device can be realistically compromised — and what
that means for your business.
This audit is designed to answer one thing clearly:
Can this device be exploited in the real world, and how?
Who It's For
- Hardware and IoT device vendors
- Product security and firmware engineering leads
- CTOs and technical founders
- Teams shipping firmware-based products (consumer IoT, industrial systems, medical devices)
What We Deliver
- Exploit chains or concrete abuse scenarios (where found).
- Reproduction steps and proof-of-concepts (when feasible).
- Executive risk summary focused on business impact.
Credibility
Bartosz Zglobicki — Independent Security Consultant
Background
- 15 years in IT
- 8 years software development (C / C++)
- 7 years offensive security (pentesting and security research)
- Former Security Consultant at F-Secure
Selected CVEs
- CVE-2020-25782
- CVE-2020-25783
- CVE-2020-25784
- CVE-2020-25785
Selected Research & Findings
-
Consumer IoT camera firmware
- Identified multiple remotely reachable memory corruption flaws.
- Demonstrated unauthenticated compromise path.
- Resulted in CVE assignments.
-
Embedded Linux device (industrial class)
- Unauthenticated privilege escalation via ssh login customization.
- Persistent compromise demonstrated.
- Client engagement (details withheld).
Contact
To discuss scope and suitability:
consulting <_a_t_> zglobicki.pl
Initial contact by email only.