Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/ivmks74/iiita-iot-security-research
Embedded Systems SecurityIoT SecurityVulnerability AnalysisReverse EngineeringNetwork SecurityDigital ForensicsFirmware Analysis
GitHubivmks74/iiita-iot-security-research

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

IIITA-IoT-Security-Research

IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.

View Repository
23 days agoNot yet reviewed

IIIT Allahabad – IoT Security Research Internship

Overview

This repository showcases the work carried out during my Research Internship at the Indian Institute of Information Technology, Allahabad (IIIT Allahabad) under the Cryptography and Network Security (CNS) Lab.

During this internship, I worked on IoT Security, Firmware Reverse Engineering, and Vulnerability Research, focusing on the security assessment of embedded IP camera firmware. The research resulted in the responsible disclosure of security vulnerabilities that were officially assigned two CVEs and published by CERT-In.


Researchers

  • Venkata Mythreya Kumara Sarma Isukapalli
  • Venkata Sesha Shaina Reddy Tiyyagura
  • Vishwa V

Internship Details

Organization: Indian Institute of Information Technology, Allahabad (IIIT Allahabad)

Research Mentor: Mr. Venkatesan Subramanian

Research Domain

  • IoT Security
  • Firmware Reverse Engineering
  • Embedded Linux
  • Vulnerability Assessment
  • Responsible Disclosure

Research Highlights

The internship involved comprehensive firmware analysis of embedded IP cameras to identify security weaknesses through reverse engineering and embedded Linux analysis.

Activities Performed

  • Firmware Extraction
  • Filesystem Analysis
  • Startup Script Analysis
  • Embedded Linux Analysis
  • Security Assessment
  • Root Cause Analysis
  • Vulnerability Validation
  • Responsible Vulnerability Disclosure

Technical Skills Demonstrated

  • Firmware Reverse Engineering
  • IoT Security
  • Embedded Linux
  • Binwalk
  • Linux Internals
  • Vulnerability Research
  • Responsible Disclosure
  • Digital Forensics
  • Network Security

Tools Used

  • Binwalk
  • FTK Imager
  • Wireshark
  • Nmap
  • Hashcat
  • Netcat
  • Linux
  • BusyBox

Official Recognition

The research has been officially acknowledged through the following publications:

CERT-In Vulnerability Note

CIVN-2026-0380

https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0380


Common Vulnerabilities and Exposures (CVEs)

CVE-2026-65893

https://www.cve.org/CVERecord?id=CVE-2026-65893

CVE-2026-65894

https://www.cve.org/CVERecord?id=CVE-2026-65894


Key Outcomes

  • Successfully identified security vulnerabilities in an IoT surveillance device.
  • Conducted firmware reverse engineering and security analysis.
  • Contributed to responsible vulnerability disclosure.
  • Research officially recognized through two CVEs and a CERT-In Vulnerability Note.
  • Strengthened practical expertise in firmware analysis, embedded Linux, and cybersecurity research.

Acknowledgements

I would like to express my sincere gratitude to:

  • Indian Institute of Information Technology, Allahabad (IIIT Allahabad)
  • Mr. Venkatesan Subramanian for his invaluable guidance and mentorship throughout the internship.
  • Vignan's Foundation for Science, Technology & Research (Deemed to be University) for providing this research opportunity.
  • Dr. Deevi Radha Rani, Head of the Department.
  • Dr. Venkatesulu Dondeti, Dean.
  • All the faculty members of the Department of Computer Science & Engineering (Cyber Security) for their continuous encouragement and support.

Disclaimer

This repository is intended solely to document my research experience and achievements.

No exploit code, proof-of-concept code, weaponized payloads, or sensitive technical details are included.

All identified vulnerabilities were responsibly disclosed to the vendor and relevant authorities before public disclosure.


Connect with Me

LinkedIn: https://www.linkedin.com/in/venkata-mythreya-kumara-sarma-isukapalli-60b4a7255

GitHub: https://github.com/ivmks74

Download Tool