Semiconductors

Fuzzing for Security-Relevant Firmware

Three campaigns in three years: Trusted Firmware-M, TPM firmware, Bluetooth stack

Hands on a laptop keyboard, above them warning symbols and program code
3fuzzing campaigns in three years

Project

Semiconductors · Cyber & Compliance

  • Global semiconductor manufacturer, security software for microcontrollers in IoT and security products
  • Fuzzing against Trusted Firmware-M (2024), TPM firmware (2025), Bluetooth stack (2026)
  • Firmware rehosting, vulnerability reports with CVSS 3.1 and proof of concept
  • Three orders from 2024 to 2026
  • approx. €235,000
  • Fixed price with measurable acceptance criteria

Challenge

  • Vulnerabilities in the firmware have a direct effect on the clients’ products
  • Systematically test unexpected inputs at the boundary between the secure and non-secure world
  • The client wants to continue fuzzing on its own after the campaign

Solution

  • Test firmware and fuzzer configuration per target, coverage target of 80% of functions, 70% of code
  • Validity of the setup proven with deliberately built-in vulnerabilities
  • Every vulnerability with a report, CVSS 3.1 and a reproducible proof of concept
  • Reproducible Docker setup handed over to the client

Result

  • Vulnerabilities found, assessed and proven before delivery
  • 2024 and 2025 campaigns accepted against coverage targets, the third is ongoing
  • The same requester commissions three campaigns in three years

Cyber & Compliance

Your next step

Get in touch now!

Whether you have a concrete project, need initial guidance or have other questions: tell us briefly what it is about.

Discuss your project