Coverage · FDIE

Firmware coverage, with the boundaries in view.

Understand which image families and analysis methods FDIE can examine, what each result can support, and where further assessment is needed. Qualify your exact firmware, packaging and engine build before relying on a workflow.

60
Unique technical checks in the source suite
11
Published framework mapping profiles
Per image
Compatibility and execution coverage

Images and artifacts

Compatibility starts with the actual image.

Support depends on packaging, available metadata and the selected analysis mode. Recognising a container or processor is a starting point. It does not guarantee that every region can be extracted, every function decompiled or every binary executed.

FDIE image and artifact coverage
SurfaceExamples and scopeCompatibility boundary
Containers and filesystemsEmbedded Linux images, vendor update wrappers, raw images and nested archives. SquashFS, UBI/UBIFS, JFFS2, CramFS, RomFS, ext2/3/4 and FAT12/16/32 families.Custom layouts, unsupported compression and damaged images can require preparation. Recognition does not establish complete extraction.
Encrypted regionsSupported schemes with available, lawfully obtained key material.Unknown encrypted regions remain unreadable. Do not send private keys through marketing or support forms.
Binary reviewRecovered ELF and PE metadata, linking, strings, disassembly and supported function analysis.Stripped or statically linked binaries and proprietary naming can reduce identification and function matching.
EmulationSupported CPU, ABI and userspace combinations for Linux binaries on MIPS, ARM, AArch64 and x86-64. Full system boot runs only where the deployment provides a compatible kernel.Drivers, peripherals, missing libraries and custom hardware can prevent execution even when the CPU is recognised.
MCU and RTOS imagesRecoverable metadata and supported static checks.Do not assume full-system runtime coverage or transfer a Linux qualification result to an MCU or RTOS image.

Analysis scope

Different methods answer different questions.

Follow the evidence from recovered artifacts to findings, runtime observations and release decisions. Review unsupported and failed stages alongside successful ones; a completed job does not imply complete security coverage.

FDIE analysis methods and interpretation
Review areaAvailable evidenceWhat still needs review
Components and vulnerabilitiesRecognised software, available versions, linking metadata and advisory matches with severity, EPSS and KEV context.Identification and feed age affect results. A version match does not establish reachability or account for every vendor backport.
Credentials, cryptography and hardeningRecoverable credential candidates, cryptographic usage, binary protections, update mechanisms and secure-boot indicators.Static indicators cannot establish hardware enforcement, effective device configuration or the absence of unrecognised secrets.
Scripts and attack surfaceSupported shipped-script checks, recovered configuration, service evidence and YARA indicators.A match requires investigation. Unrecovered files and unrecognised patterns remain outside the observed scope.
Release and function comparisonAdded, removed and changed components, available binary/function evidence and earlier triage suggestions for analyst review.Compare extraction, engine and feed context on both releases. A changed function or hash alone does not prove remediation.
Runtime and fuzzingBounded per-binary emulation, process and socket observations, and candidate crashes from supported targets; full system boot only where a compatible kernel is provided.Coverage is limited to the executed paths, inputs and time budget. Reproduce crashes and distinguish firmware faults from environment failures.
Framework evidence and exportsMapped technical checks, supported software and cryptographic inventories, recorded vulnerability dispositions and assessment reports.Exports retain the assessment's limits. Hardware assurance, organisational processes and legal applicability require additional evidence and review.

Read the result

Keep assessment gaps in the release record.

Status describes what happened during the assessment. It should travel with the findings, inventory and analyst decision, including any follow-up testing.

Complete
The job reached its completion state. Check the individual stages and targets before concluding which surfaces were assessed.
Partial
Some evidence is available, while other stages or regions could not be assessed. Retain both the findings and the reasons for incomplete work.
Unassessed
An evidence gap remains. This is not a pass, a clean result or a not-affected vulnerability disposition.
Source inventory
A published set of configured capabilities and mappings. It does not prove that a particular deployed release enabled or executed every check.

Framework mapping inventory

Inspect the checks behind each profile.

This source inventory was reviewed on 16 September 2026. Its 60 unique technical checks are mapped to 11 profiles. A check can appear in more than one profile, so profile totals must not be added together as unique checks.

Mappings identify technical references, not certification or a guarantee of the checks enabled in a deployed release. Some references address a broad mechanism family. Assess the relevant edition, product applicability and missing hardware or organisational evidence separately. CRA disclosure review is a separate workflow.

OWASP Firmware Security Testing Methodology1.0 · 47 mapped checks
Publisher reference
OWASP Firmware Security Testing Methodology: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityStage 5
TC-CRED-03 · Password hash strength assessmentCredential SecurityStage 5
TC-CRED-04 · API key and token detectionCredential SecurityStage 5
TC-CRED-05 · Embedded private key detectionCredential SecurityStage 5
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityStage 5
TC-CRED-07 · Account with no password setCredential SecurityStage 5
TC-CRYPTO-01 · MD5 usage in security contextCryptographyStage 5
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyStage 5
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyStage 5
TC-CRYPTO-04 · RSA key length validationCryptographyStage 5
TC-CRYPTO-05 · TLS version enforcementCryptographyStage 5
TC-CRYPTO-06 · Certificate validationCryptographyStage 5
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyStage 5
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyStage 5
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyStage 5
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyStage 5
TC-CRYPTO-11 · ECB block-cipher modeCryptographyStage 5
TC-BIN-01 · Stack canary detectionBinary HardeningStage 5
TC-BIN-02 · NX/DEP bit verificationBinary HardeningStage 5
TC-BIN-03 · PIE/ASLR verificationBinary HardeningStage 5
TC-BIN-04 · RELRO configurationBinary HardeningStage 5
TC-BIN-05 · Debug symbol strippingBinary HardeningStage 5
TC-BIN-06 · Insecure RPATH/RUNPATHBinary HardeningStage 5
TC-ATK-01 · Telnet service detectionAttack SurfaceStage 5
TC-ATK-02 · FTP service detectionAttack SurfaceStage 5
TC-ATK-03 · Debug tool presenceAttack SurfaceStage 5
TC-ATK-04 · UART debug shell detectionAttack SurfaceStage 5
TC-ATK-06 · Web interface privilege checkAttack SurfaceStage 5
TC-CVE-01 · OS and kernel CVE scanKnown VulnerabilitiesStage 5
TC-CVE-02 · BusyBox CVE scanKnown VulnerabilitiesStage 5
TC-CVE-03 · TLS library CVE checkKnown VulnerabilitiesStage 5
TC-CVE-05 · Known vulnerable binary hash matchKnown VulnerabilitiesStage 5
TC-CVE-06 · Firmware-wide critical CVE presenceKnown VulnerabilitiesStage 5
TC-CVE-07 · CVE regression from prior firmware versionKnown VulnerabilitiesStage 5
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown VulnerabilitiesStage 5
TC-CVE-09 · End-of-life component in the SBOMKnown VulnerabilitiesStage 5
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime BehaviourStage 7
TC-RUN-02 · Network-reachable command execution surfaceRuntime BehaviourStage 7
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceStage 5
TC-ATK-09 · Pre-authentication information disclosureAttack SurfaceStage 5
TC-ATK-10 · Redundant root-privileged accountAttack SurfaceStage 5
TC-ATK-11 · Security event logging presentAttack SurfaceStage 5
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceStage 5
TC-CODE-01 · Command or code injection in shipped scriptsCode SecurityStage 5
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode SecurityStage 5
TC-CODE-03 · Untrusted input selects a file pathCode SecurityStage 5
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode SecurityStage 5
NIST SP 800-193Final · 9 mapped checks
Publisher reference
NIST SP 800-193: configured technical mappings
Configured checkCategoryReference
TC-UPD-01 · Update signature verification presenceFirmware Update4.1.2
TC-UPD-03 · Rollback protectionFirmware Update4.1.3
TC-UPD-04 · Pre-installation integrity checkFirmware Update4.1.2
TC-UPD-05 · Unsigned update rejectionFirmware Update4.1.1
TC-ATK-11 · Security event logging presentAttack Surface4.1.4
TC-BOOT-01 · Bootloader signature verificationSecure Boot4.1.1
TC-BOOT-02 · Boot measurement capabilitySecure Boot4.2.3
TC-BOOT-03 · Recovery partition presenceSecure Boot4.3.1
TC-BOOT-04 · Runtime integrity verificationSecure Boot4.2.1
ETSI EN 303 645v2.1.1 · 44 mapped checks
Publisher reference
ETSI EN 303 645: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential Security5.1-1
TC-CRED-02 · Default credential database matchCredential Security5.1-1, 5.1-2
TC-CRED-03 · Password hash strength assessmentCredential Security5.4
TC-CRED-05 · Embedded private key detectionCredential Security5.4
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security5.4-1
TC-CRED-07 · Account with no password setCredential Security5.1-1
TC-UPD-01 · Update signature verification presenceFirmware Update5.3-3
TC-UPD-02 · Update channel encryptionFirmware Update5.3-2
TC-UPD-04 · Pre-installation integrity checkFirmware Update5.3-3
TC-CRYPTO-01 · MD5 usage in security contextCryptography5.5
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography5.5
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography5.5
TC-CRYPTO-05 · TLS version enforcementCryptography5.5
TC-CRYPTO-06 · Certificate validationCryptography5.5
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography5.5
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography5.5
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography5.5
TC-CRYPTO-11 · ECB block-cipher modeCryptography5.5
TC-ATK-01 · Telnet service detectionAttack Surface5.6-1
TC-ATK-02 · FTP service detectionAttack Surface5.6
TC-ATK-03 · Debug tool presenceAttack Surface5.6-2
TC-ATK-04 · UART debug shell detectionAttack Surface5.6
TC-ATK-05 · Unnecessary network servicesAttack Surface5.6-1
TC-ATK-06 · Web interface privilege checkAttack Surface5.6-3
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface5.2
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities5.3
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities5.3
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities5.3
TC-CVE-04 · SBOM generationKnown Vulnerabilities5.3
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities5.3
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities5.3
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities5.3
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime Behaviour5.13-1
TC-RUN-02 · Network-reachable command execution surfaceRuntime Behaviour5.13-1
TC-ATK-08 · Brute-force protection on network authenticationAttack Surface5.1-5
TC-ATK-09 · Pre-authentication information disclosureAttack Surface5.6-2
TC-ATK-10 · Redundant root-privileged accountAttack Surface5.6-3
TC-ATK-12 · Management interface served over cleartext HTTPAttack Surface5.5-1
TC-CODE-01 · Command or code injection in shipped scriptsCode Security5.13-1
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode Security5.13-1
TC-CODE-03 · Untrusted input selects a file pathCode Security5.13-1
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode Security5.13-1
TC-BOOT-01 · Bootloader signature verificationSecure Boot5.7
TC-BOOT-04 · Runtime integrity verificationSecure Boot5.7
NIST IR 8259AFinal · 17 mapped checks
Publisher reference
NIST IR 8259A: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityCapability 4
TC-CRED-02 · Default credential database matchCredential SecurityCapability 2
TC-CRED-07 · Account with no password setCredential SecurityCapability 4
TC-UPD-01 · Update signature verification presenceFirmware UpdateCapability 5
TC-UPD-02 · Update channel encryptionFirmware UpdateCapability 5
TC-CRYPTO-05 · TLS version enforcementCryptographyCapability 3
TC-CRYPTO-06 · Certificate validationCryptographyCapability 3
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyCapability 3
TC-ATK-01 · Telnet service detectionAttack SurfaceCapability 4
TC-ATK-05 · Unnecessary network servicesAttack SurfaceCapability 4
TC-CVE-01 · OS and kernel CVE scanKnown VulnerabilitiesCapability 5
TC-CVE-04 · SBOM generationKnown VulnerabilitiesCapability 6
TC-CVE-06 · Firmware-wide critical CVE presenceKnown VulnerabilitiesCapability 5
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown VulnerabilitiesCapability 5
TC-CVE-09 · End-of-life component in the SBOMKnown VulnerabilitiesCapability 5
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceCapability 4
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceCapability 3
IEC 62443-4-22019 · 36 mapped checks
Publisher reference
IEC 62443-4-2: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityCR 1.5
TC-CRED-02 · Default credential database matchCredential SecurityCR 1.1
TC-CRED-03 · Password hash strength assessmentCredential SecurityCR 1.5
TC-CRED-04 · API key and token detectionCredential SecurityCR 1.5
TC-CRED-05 · Embedded private key detectionCredential SecurityCR 1.5
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityCR 4.1
TC-CRED-07 · Account with no password setCredential SecurityCR 1.5
TC-UPD-01 · Update signature verification presenceFirmware UpdateCR 3.4
TC-CRYPTO-01 · MD5 usage in security contextCryptographyCR 4.1
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyCR 4.1
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyCR 4.1
TC-CRYPTO-04 · RSA key length validationCryptographyCR 4.1
TC-CRYPTO-05 · TLS version enforcementCryptographyCR 4.1
TC-CRYPTO-06 · Certificate validationCryptographyCR 4.1
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyCR 4.1
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyCR 4.1
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyCR 4.1
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyCR 4.1
TC-CRYPTO-11 · ECB block-cipher modeCryptographyCR 4.1
TC-ATK-01 · Telnet service detectionAttack SurfaceCR 2.1
TC-ATK-02 · FTP service detectionAttack SurfaceCR 2.1
TC-ATK-03 · Debug tool presenceAttack SurfaceCR 2.1
TC-ATK-04 · UART debug shell detectionAttack SurfaceCR 2.1
TC-ATK-05 · Unnecessary network servicesAttack SurfaceCR 2.1
TC-ATK-06 · Web interface privilege checkAttack SurfaceCR 2.1
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime BehaviourCR 3.5
TC-RUN-02 · Network-reachable command execution surfaceRuntime BehaviourCR 3.5
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceCR 1.11
TC-ATK-10 · Redundant root-privileged accountAttack SurfaceCR 2.1
TC-ATK-11 · Security event logging presentAttack SurfaceCR 6.1
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceCR 4.1
TC-CODE-01 · Command or code injection in shipped scriptsCode SecurityCR 3.5
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode SecurityCR 3.5
TC-CODE-03 · Untrusted input selects a file pathCode SecurityCR 3.5
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode SecurityCR 3.5
TC-BOOT-01 · Bootloader signature verificationSecure BootCR 3.4
EN 18031-12024 · 45 mapped checks
Publisher reference
EN 18031-1: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityAUM-1
TC-CRED-02 · Default credential database matchCredential SecurityAUM-1
TC-CRED-03 · Password hash strength assessmentCredential SecurityAUM-1
TC-CRED-04 · API key and token detectionCredential SecurityAUM-1
TC-CRED-05 · Embedded private key detectionCredential SecurityAUM-1
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityAUM-1
TC-CRED-07 · Account with no password setCredential SecurityAUM-1
TC-UPD-01 · Update signature verification presenceFirmware UpdateSUM-1
TC-UPD-02 · Update channel encryptionFirmware UpdateSUM-1
TC-UPD-03 · Rollback protectionFirmware UpdateSUM-1
TC-UPD-04 · Pre-installation integrity checkFirmware UpdateSUM-1
TC-UPD-05 · Unsigned update rejectionFirmware UpdateSUM-1
TC-CRYPTO-01 · MD5 usage in security contextCryptographyCRY-1
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyCRY-1
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyCRY-1
TC-CRYPTO-04 · RSA key length validationCryptographyCRY-1
TC-CRYPTO-05 · TLS version enforcementCryptographyCRY-1
TC-CRYPTO-06 · Certificate validationCryptographyCRY-1
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyCRY-1
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyCRY-1
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyCRY-1
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyCRY-1
TC-CRYPTO-11 · ECB block-cipher modeCryptographyCRY-1
TC-BIN-01 · Stack canary detectionBinary HardeningGEC-1
TC-BIN-02 · NX/DEP bit verificationBinary HardeningGEC-1
TC-BIN-03 · PIE/ASLR verificationBinary HardeningGEC-1
TC-BIN-04 · RELRO configurationBinary HardeningGEC-1
TC-BIN-05 · Debug symbol strippingBinary HardeningGEC-1
TC-BIN-06 · Insecure RPATH/RUNPATHBinary HardeningGEC-1
TC-ATK-01 · Telnet service detectionAttack SurfaceGEC-2
TC-ATK-02 · FTP service detectionAttack SurfaceGEC-2
TC-ATK-03 · Debug tool presenceAttack SurfaceGEC-2
TC-ATK-04 · UART debug shell detectionAttack SurfaceGEC-2
TC-ATK-05 · Unnecessary network servicesAttack SurfaceGEC-2
TC-ATK-06 · Web interface privilege checkAttack SurfaceGEC-2
TC-ATK-07 · Vulnerability disclosure policy presenceAttack SurfaceGEC-2
TC-ATK-08 · Brute-force protection on network authenticationAttack SurfaceGEC-2
TC-ATK-09 · Pre-authentication information disclosureAttack SurfaceGEC-2
TC-ATK-10 · Redundant root-privileged accountAttack SurfaceGEC-2
TC-ATK-11 · Security event logging presentAttack SurfaceGEC-2
TC-ATK-12 · Management interface served over cleartext HTTPAttack SurfaceGEC-2
TC-BOOT-01 · Bootloader signature verificationSecure BootRLM-1
TC-BOOT-02 · Boot measurement capabilitySecure BootRLM-1
TC-BOOT-03 · Recovery partition presenceSecure BootRLM-1
TC-BOOT-04 · Runtime integrity verificationSecure BootRLM-1
EN 18031-22024 · 18 mapped checks
Publisher reference
EN 18031-2: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential SecuritySSM-1
TC-CRED-02 · Default credential database matchCredential SecuritySSM-1
TC-CRED-03 · Password hash strength assessmentCredential SecuritySSM-1
TC-CRED-04 · API key and token detectionCredential SecuritySSM-1
TC-CRED-05 · Embedded private key detectionCredential SecuritySSM-1
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecuritySSM-1
TC-CRED-07 · Account with no password setCredential SecuritySSM-1
TC-CRYPTO-01 · MD5 usage in security contextCryptographySCM-1
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographySCM-1
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographySCM-1
TC-CRYPTO-04 · RSA key length validationCryptographySCM-1
TC-CRYPTO-05 · TLS version enforcementCryptographySCM-1
TC-CRYPTO-06 · Certificate validationCryptographySCM-1
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographySCM-1
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographySCM-1
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographySCM-1
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographySCM-1
TC-CRYPTO-11 · ECB block-cipher modeCryptographySCM-1
EN 18031-32024 · 23 mapped checks
Publisher reference
EN 18031-3: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential SecurityRED 3.3(f) - AUM
TC-CRED-02 · Default credential database matchCredential SecurityRED 3.3(f) - AUM
TC-CRED-03 · Password hash strength assessmentCredential SecurityRED 3.3(f) - AUM
TC-CRED-04 · API key and token detectionCredential SecurityRED 3.3(f) - AUM
TC-CRED-05 · Embedded private key detectionCredential SecurityRED 3.3(f) - AUM
TC-CRED-06 · Credentials stored in clear text on the deviceCredential SecurityRED 3.3(f) - AUM
TC-CRED-07 · Account with no password setCredential SecurityRED 3.3(f) - AUM
TC-UPD-01 · Update signature verification presenceFirmware UpdateRED 3.3(f) - SUM
TC-UPD-02 · Update channel encryptionFirmware UpdateRED 3.3(f) - SUM
TC-UPD-03 · Rollback protectionFirmware UpdateRED 3.3(f) - SUM
TC-UPD-04 · Pre-installation integrity checkFirmware UpdateRED 3.3(f) - SUM
TC-UPD-05 · Unsigned update rejectionFirmware UpdateRED 3.3(f) - SUM
TC-CRYPTO-01 · MD5 usage in security contextCryptographyRED 3.3(f) - CRY
TC-CRYPTO-02 · SHA-1 usage in security contextCryptographyRED 3.3(f) - CRY
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-04 · RSA key length validationCryptographyRED 3.3(f) - CRY
TC-CRYPTO-05 · TLS version enforcementCryptographyRED 3.3(f) - CRY
TC-CRYPTO-06 · Certificate validationCryptographyRED 3.3(f) - CRY
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptographyRED 3.3(f) - CRY
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-09 · Broken hash algorithm (MD4)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)CryptographyRED 3.3(f) - CRY
TC-CRYPTO-11 · ECB block-cipher modeCryptographyRED 3.3(f) - CRY
IEC 81001-5-12021 · 39 mapped checks
Publisher reference
IEC 81001-5-1: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential Security5.2.2
TC-CRED-02 · Default credential database matchCredential Security5.2.2
TC-CRED-03 · Password hash strength assessmentCredential Security5.2.2
TC-CRED-04 · API key and token detectionCredential Security5.2.2
TC-CRED-05 · Embedded private key detectionCredential Security5.2.2
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security5.2.2
TC-CRED-07 · Account with no password setCredential Security5.2.2
TC-UPD-01 · Update signature verification presenceFirmware Update7.2
TC-UPD-02 · Update channel encryptionFirmware Update7.2
TC-UPD-03 · Rollback protectionFirmware Update7.2
TC-UPD-04 · Pre-installation integrity checkFirmware Update7.2
TC-UPD-05 · Unsigned update rejectionFirmware Update7.2
TC-CRYPTO-01 · MD5 usage in security contextCryptography4.2
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography4.2
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography4.2
TC-CRYPTO-04 · RSA key length validationCryptography4.2
TC-CRYPTO-05 · TLS version enforcementCryptography4.2
TC-CRYPTO-06 · Certificate validationCryptography4.2
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptography4.2
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography4.2
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography4.2
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography4.2
TC-CRYPTO-11 · ECB block-cipher modeCryptography4.2
TC-BIN-01 · Stack canary detectionBinary Hardening5.4
TC-BIN-02 · NX/DEP bit verificationBinary Hardening5.4
TC-BIN-03 · PIE/ASLR verificationBinary Hardening5.4
TC-BIN-04 · RELRO configurationBinary Hardening5.4
TC-BIN-05 · Debug symbol strippingBinary Hardening5.4
TC-BIN-06 · Insecure RPATH/RUNPATHBinary Hardening5.4
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface6.2
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities6.1
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities6.1
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities6.1
TC-CVE-04 · SBOM generationKnown Vulnerabilities5.2.4
TC-CVE-05 · Known vulnerable binary hash matchKnown Vulnerabilities6.1
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities6.1
TC-CVE-07 · CVE regression from prior firmware versionKnown Vulnerabilities6.1
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities6.1
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities6.1
FDA Premarket Cybersecurity (524B)2023 · 60 mapped checks
Publisher reference
FDA Premarket Cybersecurity (524B): configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential Security(b)(1)
TC-CRED-02 · Default credential database matchCredential Security(b)(1)
TC-CRED-03 · Password hash strength assessmentCredential Security(b)(1)
TC-CRED-04 · API key and token detectionCredential Security(b)(1)
TC-CRED-05 · Embedded private key detectionCredential Security(b)(1)
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security(b)(1)
TC-CRED-07 · Account with no password setCredential Security(b)(1)
TC-UPD-01 · Update signature verification presenceFirmware Update(b)(1)
TC-UPD-02 · Update channel encryptionFirmware Update(b)(1)
TC-UPD-03 · Rollback protectionFirmware Update(b)(1)
TC-UPD-04 · Pre-installation integrity checkFirmware Update(b)(1)
TC-UPD-05 · Unsigned update rejectionFirmware Update(b)(1)
TC-CRYPTO-01 · MD5 usage in security contextCryptography(b)(1)
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography(b)(1)
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography(b)(1)
TC-CRYPTO-04 · RSA key length validationCryptography(b)(1)
TC-CRYPTO-05 · TLS version enforcementCryptography(b)(1)
TC-CRYPTO-06 · Certificate validationCryptography(b)(1)
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptography(b)(1)
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography(b)(1)
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography(b)(1)
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography(b)(1)
TC-CRYPTO-11 · ECB block-cipher modeCryptography(b)(1)
TC-BIN-01 · Stack canary detectionBinary Hardening(b)(2)
TC-BIN-02 · NX/DEP bit verificationBinary Hardening(b)(2)
TC-BIN-03 · PIE/ASLR verificationBinary Hardening(b)(2)
TC-BIN-04 · RELRO configurationBinary Hardening(b)(2)
TC-BIN-05 · Debug symbol strippingBinary Hardening(b)(2)
TC-BIN-06 · Insecure RPATH/RUNPATHBinary Hardening(b)(2)
TC-ATK-01 · Telnet service detectionAttack Surface(b)(2)
TC-ATK-02 · FTP service detectionAttack Surface(b)(2)
TC-ATK-03 · Debug tool presenceAttack Surface(b)(2)
TC-ATK-04 · UART debug shell detectionAttack Surface(b)(2)
TC-ATK-05 · Unnecessary network servicesAttack Surface(b)(2)
TC-ATK-06 · Web interface privilege checkAttack Surface(b)(2)
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface(b)(2)
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities(b)(2)
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities(b)(2)
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities(b)(2)
TC-CVE-04 · SBOM generationKnown Vulnerabilities(b)(3)
TC-CVE-05 · Known vulnerable binary hash matchKnown Vulnerabilities(b)(2)
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities(b)(2)
TC-CVE-07 · CVE regression from prior firmware versionKnown Vulnerabilities(b)(2)
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities(b)(2)
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities(b)(2)
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime Behaviour(b)(2)
TC-RUN-02 · Network-reachable command execution surfaceRuntime Behaviour(b)(2)
TC-ATK-08 · Brute-force protection on network authenticationAttack Surface(b)(2)
TC-ATK-09 · Pre-authentication information disclosureAttack Surface(b)(2)
TC-ATK-10 · Redundant root-privileged accountAttack Surface(b)(2)
TC-ATK-11 · Security event logging presentAttack Surface(b)(2)
TC-ATK-12 · Management interface served over cleartext HTTPAttack Surface(b)(2)
TC-CODE-01 · Command or code injection in shipped scriptsCode Security(b)(2)
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode Security(b)(2)
TC-CODE-03 · Untrusted input selects a file pathCode Security(b)(2)
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode Security(b)(2)
TC-BOOT-01 · Bootloader signature verificationSecure Boot(b)(1)
TC-BOOT-02 · Boot measurement capabilitySecure Boot(b)(1)
TC-BOOT-03 · Recovery partition presenceSecure Boot(b)(1)
TC-BOOT-04 · Runtime integrity verificationSecure Boot(b)(1)
TEC 31318 Code of Practice for Securing Consumer IoTTEC 31318:2025 Release 2.0 · 59 mapped checks
Publisher reference
TEC 31318 Code of Practice for Securing Consumer IoT: configured technical mappings
Configured checkCategoryReference
TC-CRED-01 · Hardcoded credential detectionCredential Security3.1
TC-CRED-02 · Default credential database matchCredential Security3.1
TC-CRED-03 · Password hash strength assessmentCredential Security3.4
TC-CRED-04 · API key and token detectionCredential Security3.4
TC-CRED-05 · Embedded private key detectionCredential Security3.4
TC-CRED-06 · Credentials stored in clear text on the deviceCredential Security3.4
TC-CRED-07 · Account with no password setCredential Security3.1
TC-UPD-01 · Update signature verification presenceFirmware Update3.3
TC-UPD-02 · Update channel encryptionFirmware Update3.3
TC-UPD-04 · Pre-installation integrity checkFirmware Update3.3
TC-UPD-05 · Unsigned update rejectionFirmware Update3.3
TC-CRYPTO-01 · MD5 usage in security contextCryptography3.5
TC-CRYPTO-02 · SHA-1 usage in security contextCryptography3.5
TC-CRYPTO-03 · Deprecated cipher detection (DES/3DES/RC4)Cryptography3.5
TC-CRYPTO-04 · RSA key length validationCryptography3.5
TC-CRYPTO-05 · TLS version enforcementCryptography3.5
TC-CRYPTO-06 · Certificate validationCryptography3.5
TC-CRYPTO-07 · Hardcoded IV/salt detectionCryptography3.5
TC-CRYPTO-08 · Deprecated SSL protocol versions (SSLv2/SSLv3)Cryptography3.5
TC-CRYPTO-09 · Broken hash algorithm (MD4)Cryptography3.5
TC-CRYPTO-10 · Weak or null cipher (RC2, null cipher suite)Cryptography3.5
TC-CRYPTO-11 · ECB block-cipher modeCryptography3.5
TC-BIN-01 · Stack canary detectionBinary Hardening3.6
TC-BIN-02 · NX/DEP bit verificationBinary Hardening3.6
TC-BIN-03 · PIE/ASLR verificationBinary Hardening3.6
TC-BIN-04 · RELRO configurationBinary Hardening3.6
TC-BIN-05 · Debug symbol strippingBinary Hardening3.6
TC-BIN-06 · Insecure RPATH/RUNPATHBinary Hardening3.6
TC-ATK-01 · Telnet service detectionAttack Surface3.6
TC-ATK-02 · FTP service detectionAttack Surface3.6
TC-ATK-03 · Debug tool presenceAttack Surface3.6
TC-ATK-04 · UART debug shell detectionAttack Surface3.6
TC-ATK-05 · Unnecessary network servicesAttack Surface3.6
TC-ATK-06 · Web interface privilege checkAttack Surface3.6
TC-ATK-07 · Vulnerability disclosure policy presenceAttack Surface3.2
TC-CVE-01 · OS and kernel CVE scanKnown Vulnerabilities3.3
TC-CVE-02 · BusyBox CVE scanKnown Vulnerabilities3.3
TC-CVE-03 · TLS library CVE checkKnown Vulnerabilities3.3
TC-CVE-04 · SBOM generationKnown Vulnerabilities3.3
TC-CVE-05 · Known vulnerable binary hash matchKnown Vulnerabilities3.3
TC-CVE-06 · Firmware-wide critical CVE presenceKnown Vulnerabilities3.3
TC-CVE-07 · CVE regression from prior firmware versionKnown Vulnerabilities3.3
TC-CVE-08 · Any component has a HIGH-or-above or known-exploited CVEKnown Vulnerabilities3.3
TC-CVE-09 · End-of-life component in the SBOMKnown Vulnerabilities3.3
TC-RUN-01 · Memory-safety fault under adversarial inputRuntime Behaviour3.13
TC-RUN-02 · Network-reachable command execution surfaceRuntime Behaviour3.13
TC-ATK-08 · Brute-force protection on network authenticationAttack Surface3.1
TC-ATK-09 · Pre-authentication information disclosureAttack Surface3.1, 3.6
TC-ATK-10 · Redundant root-privileged accountAttack Surface3.6
TC-ATK-11 · Security event logging presentAttack Surface3.10
TC-ATK-12 · Management interface served over cleartext HTTPAttack Surface3.5
TC-CODE-01 · Command or code injection in shipped scriptsCode Security3.13
TC-CODE-02 · Untrusted input rendered by the device web interfaceCode Security3.13
TC-CODE-03 · Untrusted input selects a file pathCode Security3.13
TC-CODE-04 · Untrusted data parsed by an interpreter or databaseCode Security3.13
TC-BOOT-01 · Bootloader signature verificationSecure Boot3.7
TC-BOOT-02 · Boot measurement capabilitySecure Boot3.7
TC-BOOT-03 · Recovery partition presenceSecure Boot3.9
TC-BOOT-04 · Runtime integrity verificationSecure Boot3.7

Source mapping SHA-256: a13128efb566020e8eef43058129008ea1dde9ffbee947c81dc88b451ec791b7

This identifies the published source inventory, not a customer assessment or a certification record.

How FDIE supports assessment evidence

Qualify your firmware

Evaluate a representative product family.

Start with an authorised image whose contents your engineering team understands. Keep a reproducible record of what was recovered, which checks ran and what remains outside the assessment.

Repeat qualification when packaging, architecture or a major analysis version changes. A shared CPU name alone is not enough to carry a result from one product to another.

  1. Record the image assumptions

    Capture its identity, container format, known CPU family, operating-system assumptions and selected analysis build.

  2. Check extraction

    Compare recovered files and binaries with what the engineering team expects. Record encrypted, damaged or unsupported regions.

  3. Separate static and runtime results

    Review each method independently. Successful extraction does not prove that a binary ran or that a system booted.

  4. Use an independent reference

    Keep a known component or test case to check the output. Investigate unexplained identification or coverage differences.

  5. Record the remaining work

    Assign manual, hardware or additional testing for unanswered questions, and keep those limitations with the release decision.