FirmLens: Automated Static, Hardware-Rooted, and Dynamic HIL Vulnerability Analysis for Bare-Metal ESP32 Firmware
Srikanth Rudrarapu · Zenodo (CERN European Organization for Nuclear Research) · 2026
The proliferation of bare-metal and monolithic real-time operating systems (RTOS) in Internet of Things (IoT) deployments has exacerbated physical and supply-chain vulnerabilities. Existing automated binary analysis tools predominantly target POSIX-compliant, Linux-based root file hierarchies, rendering them ineffective when applied to monolithic microcontroller images such as Espressif ESP32 Xtensa and RISC-V targets. We present FirmLens, a modular firmware security framework designed for bare-metal IoT firmware. FirmLens integrates semantic partition table parsing, hardware-rooted cryptographic boot verification (Secure Boot V2, Flash Encryption), pattern-driven static vulnerability scanning, threat intelligence correlation (FIRST EPSS and CISA KEV), and provides an operational pilot for dynamic Hardware-in-the-Loop (HIL) UART crash telemetry ingestion. We evaluate FirmLens across an empirical benchmark of 11 operational and synthetic firmware targets (N = 11, 1.31 MB to 8.88 MB). On this controlled ground-truth benchmark, FirmLens achieves complete agreement against benchmark ground truth across 10 targeted CWE classes (310 findings) with a mean static analysis latency of 0.8176 ± 0.4415 s (3.93 MB/s throughput). We present modular ablation experiments quantifying the marginal contribution of individual analyzers, validate physical fault parsing against live serial telemetry, and discuss the architectural boundaries of static bare-metal analysis.