Prompt and vulnerable: a security analysis of LLM-integrated IoT firmware.
This study presents an analysis of firmware vulnerabilities of IoT devices that either include Large Language Model (LLM) communication tools or can be connected to a platform with such tools. We used device mapping with SBOM and static firmware analysis techniques with Netrise to analyze the firmware of 75 LLM-integrated IoT devices. The results showed that dangerous vulnerabilities were present in a large percentage of IoT firmware samples analyzed, exposing the LLM-integrated systems to unforeseen risk. In this paper, we review the vulnerabilities found in the firmware and discuss the possible mitigation steps needed to defend the networks from these vulnerabilities. This research contributes to the existing pool of studies in two ways: first, we analyzed a large sample of both common and non-mainstream devices. Second, we look at both vulnerabilities of IoT device firmware and those of the LLM-integrated platforms to which these devices can be connected.
