Universal Plug and Pwn
2026-09-19 , Tesla

In under an hour we will show how cheap IoT devices can expose serious security risks in your home network

We analyzed a range of low-cost connected devices and will present
the best vulnerabilities we found.

Following our analysis of low low-cost connected devices, we will give an introduction to IoT pentesting.
Concretely we present our methodology to analyze real-world devices and
present our findings and uncovered exploitation paths.

Finally we will talk about mitigations and discuss why exploiting IoT devices in 2026 is still as easy as
a decade ago.


The talk will cover the following topics:

  • Opening up the devices
  • Dumping the Firmware
  • Firmware Reverse Engineering
  • Identifying interesting entry points
  • Vulnerabilities we uncovered
  • Mitigations
  • Keeping your own devices safe

This talk is suitable for beginners.
We will show how to start analyzing your own devices, and how easy it is to exploit devices where security was not a priority during development.

Andreas is a student at Graz University of Technology with a strong interest in offensive security, systems programming, and low-level exploitation. My work focuses on understanding software at the boundary between source code, binaries, operating systems, and hardware, with a particular interest in vulnerability research, reverse engineering, and binary exploitation.

I am a master student at Graz University of Technology with a major in Information Security. I'm passionate about security, privacy, automation and I love building IT infrastructure.

Website: https://saiger.dev
Github: https://github.com/csskevin