I will analyze your firmware for security vulnerabilities

Canada

I speak English

52 orders completed

Reverse engineering reality

I reverse engineer firmware and compiled software without source code or documentation. Recent work includes CVE-2026-20161, a Linux privilege-escalation flaw; root-level vulnerabilities in enterprise...

Level 1

Has met certain performance criteria and shows strong potential in the marketplace.

About this Gig

Need a security review of an embedded device or firmware?


I perform authorized black-box analysis of embedded Linux, IoT products, and compiled firmware. Each engagement is evidence-driven and scoped to your target, not a generic automated scan.


ASSESSMENT AREAS


  • Firmware extraction and static/dynamic analysis
  • Attack surface and network services
  • Authentication and authorization
  • Hardcoded secrets and unsafe configuration
  • Command injection and privilege boundaries
  • Filesystem, IPC, and permissions


DELIVERABLES


  • Technical report with supporting evidence
  • Reproduction steps and safe PoC when applicable
  • CVSS/CWE classification for confirmed vulnerabilities
  • Remediation guidance
  • Executive summary and documented limitations


BACKGROUND


My work includes a published Cisco CVE, vendor-confirmed root-level flaws in enterprise VPN software, authorization failures in IoT security cameras, and upstream Linux kernel work. I routinely analyze targets without source code or vendor documentation.


Message me before ordering with the device or firmware, platform, testing goal, and scope.

You must own the target or have explicit authorization to test it.

Platform:

Other

Expertise:

Firmware development

RTOS

Debugging

Microcontrollers

My Portfolio