Return
A Comprehensive Empirical Study of Security Vulnerabilities in IoT Gateway Software
D
F
M
DOI:10.1109/jiot.2026.3703749.png)
Abstract
En 中文
Internet of Things (IoT) gateways play a critical role in interconnecting heterogeneous devices, local networks, and cloud infrastructures. Vulnerabilities affecting these devices pose significant security risks. Despite this relevance, existing studies primarily focus on generic IoT assets, leading to high false-positive rates, incomplete coverage, and limited insight into root causes of vulnerabilities in IoT gateways. This article presents a comprehensive empirical study of security vulnerabilities in IoT gateway software, supported by a systematic methodology for asset identification and validation. This work offers the first curated dataset focused exclusively on IoT gateways, comprising 483 validated Common Vulnerabilities and Exposures (CVEs) obtained through iterative glossary refinement, automated vulnerability collection, and expert adjudication supported by explicit scope criteria and a full-consensus acceptance protocol. The dataset is mapped to the Common Weakness Enumeration (CWE)-1000 Research View, enabling hierarchical root-cause traversal for 80.3% of the vulnerabilities. The empirical analysis reveals a high-risk vulnerability profile, with most issues affecting operating-system-level components and scoring high or critical severity. The results identify improper control of resources (CWE-664), improper neutralization (CWE-707), and improper access control (CWE-284) as the dominant root causes across IoT gateways. A qualitative decomposition of these three pillars reveals recurring concrete weaknesses (buffer overflows, OS command injection, and missing authentication for critical functions) that individually account for the majority of high-severity exploitation outcomes. These findings reveal systemic weaknesses in gateway software stacks and development practices, offering insights to improve the architectural resilience and secure design of IoT gateway platforms.
Keywords:
Common Vulnerabilities and Exposures (CVE)–Common Weakness Enumeration (CWE) mapping
Internet of Things (IoT)
IoT gateways
root-cause analysis
security vulnerabilities
Journal
IF:
8.9
Papers:
1.4W
Citations:
7.8W
