Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
FirmAE — Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis | Kitploit
Tools/GitHubGitHub/pr0v3rbs/firmae
Embedded Systems SecurityDynamic Analysis (Sandboxing)IoT SecurityVulnerability AnalysisWeb SecurityFirmware AnalysisTop in Embedded Systems Security #4Top in Firmware Analysis #4Top in IoT Security #4
894147142 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubpr0v3rbs/firmae

FirmAE

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

View Repository

FirmAE

FirmAE is a fully-automated framework that performs emulation and vulnerability analysis. FirmAE significantly increases the emulation success rate (From Firmadyne's 16.28% to 79.36%) with five arbitration techniques. We tested FirmAE on 1,124 wireless-router and IP-camera firmware images from top eight vendors.

We also developed a dynamic analysis tool for 0-day discovery, which infers web service information based on the filesystem and kernel logs of target firmware. By running our tool on the succesfully emulation firmware images, we discovered 12 new 0-days which affect 23 devices.

Installation

Note that we tested FirmAE on Ubuntu 20.04.

  1. Clone FirmAE
root@kitploit:~
$ git clone --recursive https://github.com/pr0v3rbs/FirmAE
  1. Run download.sh script.
root@kitploit:~
$ ./download.sh
  1. Run install.sh script.
root@kitploit:~
$ ./install.sh

Usage

  1. Execute init.sh script.
root@kitploit:~
$ ./init.sh
  1. Prepare a firmware.
root@kitploit:~
$ wget https://github.com/pr0v3rbs/FirmAE/releases/download/v1.0/DIR-868L_fw_revB_2-05b02_eu_multi_20161117.zip
  1. Check emulation
root@kitploit:~
$ sudo ./run.sh -c <brand> <firmware>
  1. Analyze the target firmware
  • Analysis mode uses the FirmAE analyzer
root@kitploit:~
$ sudo ./run.sh -a <brand> <firmware>
  • Run mode helps to test web service or execute custom analyzer
root@kitploit:~
$ sudo ./run.sh -r <brand> <firmware>

Debug

After run.sh -c finished.

1. User-level basic debugging utility.

Useful when an emulated firmware is network reachable or not

  • It supports socat connection, nc reverse shell (31337) and telnet connection (31338)
  • And the setup will be done automatically
root@kitploit:~
$ sudo ./run.sh -d <brand> <firmware>

2. Kernel-level boot debugging.

root@kitploit:~
$ sudo ./run.sh -b <brand> <firmware>

Turn on/off arbitration

Check the five arbitrations environment variable in the firmae.config

root@kitploit:~
$ head firmae.config
#!/bin/sh

FIRMAE_BOOT=true
FIRMAE_NETWORK=true
FIRMAE_NVRAM=true
FIRMAE_KERNEL=true
FIRMAE_ETC=true

if (${FIRMAE_ETC}); then
  TIMEOUT=240

Docker

First, prepare a docker image.

root@kitploit:~
$ ./docker-init.sh

Parallel mode

Then, run one of the below commands. -ec checks only the emulation, and -ea checks the emulation and analyzes vulnerabilities.

root@kitploit:~
$ ./docker-helper.py -ec <brand> <firmware>
$ ./docker-helper.py -ea <brand> <firmware>

Here, <firmware> can be a text file that lists the paths of firmware image. Check the sample file at ./examples/test.list.

Debug mode

After a firmware image successfully emulated.

root@kitploit:~
$ ./docker-helper.py -ed <firmware>

Evaluation

Emulation result

Google spreadsheet - view

Dataset

Google drive - download

CVEs

ASUS

  • CVE-2019-20082

Belkin

  • Belkin01

D-Link

  • CVE-2018-20114
  • CVE-2018-19986
  • CVE-2018-19987
  • CVE-2018-19988
  • CVE-2018-19989
  • CVE-2018-19990
  • CVE-2019-6258
  • CVE-2019-20084

TRENDNet

  • CVE-2019-11399
  • CVE-2019-11400

Authors

This research project has been conducted by SysSec Lab at KAIST.

  • Mingeun Kim
  • Dongkwan Kim
  • Eunsoo Kim
  • Suryeon Kim
  • Yeongjin Jang
  • Yongdae Kim

Citation

We would appreciate if you consider citing our paper when using FirmAE.

root@kitploit:~
@inproceedings{kim:2020:firmae,
  author = {Mingeun Kim and Dongkwan Kim and Eunsoo Kim and Suryeon Kim and Yeongjin Jang and Yongdae Kim},
  title = {{FirmAE}: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis},
  booktitle = {Annual Computer Security Applications Conference (ACSAC)},
  year = 2020,
  month = dec,
  address = {Online}
}
Download Tool