Research Article

Discovering Vulnerabilities in COTS IoT Devices through Blackbox Fuzzing Web Management Interface

Table 2

Summary of discovered vulnerabilities.

DeviceVul-IDVulnerabilityRemotely exploitableCNVD-IDAddition

Phicomm K2-A6001Command injectionTrueCNVD-2017-25289Fixed
002Interface leakTrueCNVD-2017-20666Fixed

JieXi AC836M003CrashTrueN-dayFixed

FeiYuXing VE602W+004Interface leakTrueCNVD-2017-35720Fixed
005Command injectionTrueFixed

RuiJie NBR1300G006CrashFalseJust-a-DosFixed
007Command injectionTrueCNVD-2018-22138Fixed

RIWYTH RW-950S008Interface leakTrueCNVD-2017-37032Fixed

NEO NIP-25SY009CrashFalseN-dayFixed

ZTE C520P010Interface leakTrueCNVD-2018-21990Fixed