Back to Case Studies
Pentest IoT Security

IoT Device Penetration Test for a Physical Security Integrator

Found a hardcoded, publicly-known administrator credential baked into the camera's firmware — identical across every unit of that model in the client's fleet — and delivered a phased remediation roadmap ahead of active botnet exploitation targeting the same device class.

Client: Ukrainian Physical Security & Video Surveillance Integrator

Industry
Physical Security · Video Surveillance
Engagement
Black-box + firmware-level penetration test · Single representative IP camera device, IoT scope
23
Total findings
1
Critical findings
Every unit, same model
Devices affected

Challenge

The client integrates and operates IP camera systems for its own customers' physical security. Camera hardware and firmware come from a single vendor across the fleet, and the client had no independent assurance the devices themselves — as opposed to the software layer they control — were sound. IoT camera botnets were an active, rising threat class, and a single systemic firmware flaw could compromise every deployed unit at once rather than one customer site.

Approach

Rather than a typical network-only device audit, the engagement went a layer deeper: web/API testing, IoT protocol exploitation across device management and streaming protocols, live traffic analysis, and full firmware reverse engineering — flash extraction, filesystem analysis, credential recovery, and boot-chain review. The goal was to test real-world exploitability, not just enumerate theoretical exposure.

Key Activities

  • Extracted and reverse-engineered the device firmware image — filesystem, boot chain, and update mechanism
  • Captured and analyzed live network traffic across the management API and device protocols
  • Recovered and cracked credential hashes pulled from firmware to confirm real-world, not theoretical, exploitability
  • Cross-referenced the underlying vendor platform against public vulnerability records and live botnet-activity intelligence
  • Mapped multi-step attack chains from initial network position through to full device takeover
  • Delivered a phased, priority-ordered remediation roadmap ranked by real-world exploitability, not just severity score

Results

Identified a hardcoded, factory-set administrator credential in the device firmware — identical across every unit of that model — publicly known for years and still present in the firmware build shipped to the client
Found management traffic was unencrypted by default, letting session credentials be captured and reused for full administrative control by anyone on the local network
Confirmed the vendor's underlying platform was an active target of a Mirai-variant botnet that had already compromised roughly 30,000 devices worldwide
Mapped four realistic attack chains — network interception, password-recovery abuse, operator-workstation compromise, and physical firmware access — each ending in full device takeover, one of which survives a full credential rotation

Business Impact

Gave the client hard, reproduced evidence of exactly how exploitable its camera fleet was — not vendor marketing claims — ahead of any real incident
Delivered a prioritized, phased fix roadmap the client's team could execute without needing in-house firmware security expertise
Connected the findings to live, real-world botnet activity, turning an abstract CVE reference into a concrete, urgent business-risk conversation

Technologies & Service Areas

Firmware Reverse Engineering IoT Device Testing Network Protocol Analysis Embedded Systems Security

Related Services

Client names and identifying details are withheld. This case study is a sanitized account shared with the client's consent.