EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing Analysis

Hangtian Liu

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · IoT Security

Overview

The proliferation of Internet of Things (IoT) devices has brought unprecedented convenience, but it has also opened a Pandora's box of security vulnerabilities. Among the myriad threats, hidden web interfaces stand out as a particularly insidious and often overlooked problem. These undocumented and untraceable access points provide undisclosed backdoors for attackers, potentially leading to severe security incidents without any clear indication of their existence or purpose to legitimate users or administrators. Traditional vulnerability discovery methods often fall short in identifying these interfaces due to their clandestine nature, lacking clear patterns for static analysis or discernible feedback for dynamic testing.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction and hidden web interface definition
  2. 2:00 Challenges in discovering hidden web interfaces
  3. 2:40 Eagle Eye's intuition: focusing on routing tokens
  4. 3:45 Eagle Eye's two-stage solution overview
  5. 4:50 Leveraging ARM for routing token pattern learning
  6. 6:00 Self-correction model for pattern refinement
  7. 8:00 Evaluation results: 79 hidden interfaces found
  8. 9:00 Comparison with IoT Scoop and automation benefits

EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing Analysis

Speakers: Hangtian Liu

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=qXDD2iiIeCg

Overview

The proliferation of Internet of Things (IoT) devices has brought unprecedented convenience, but it has also opened a Pandora's box of security vulnerabilities. Among the myriad threats, hidden web interfaces stand out as a particularly insidious and often overlooked problem. These undocumented and untraceable access points provide undisclosed backdoors for attackers, potentially leading to severe security incidents without any clear indication of their existence or purpose to legitimate users or administrators. Traditional vulnerability discovery methods often fall short in identifying these interfaces due to their clandestine nature, lacking clear patterns for static analysis or discernible feedback for dynamic testing.

This talk, presented by Hangtian Liu at the NDSS Symposium, introduces EagleEye, a novel solution designed to systematically uncover these elusive hidden web interfaces in IoT devices. EagleEye models the problem as a search process, leveraging a two-stage approach: intelligent routing analysis and directed blackbox fuzzing. By focusing on the underlying routing mechanisms that govern how devices process requests, EagleEye deduces patterns from public interfaces to uncover their hidden counterparts.

The significance of EagleEye's research is profound. It not only provides a clear definition and methodology for identifying hidden web interfaces but also demonstrates their widespread prevalence and severe security implications. The team successfully exposed 79 hidden interfaces across 13 commercial IoT devices from leading manufacturers, leading to the discovery of 29 unknown vulnerabilities, including backdoors, with 7 instances already assigned CVEs. This work underscores an urgent need for IoT manufacturers to re-evaluate their development practices and for the security community to integrate such sophisticated tools into their defensive strategies.

Background

▶ Watch: Introduction and hidden web interface definition (0:00)

The concept of an "interface" in an IoT device context refers to a gateway that allows clients to access specific functionalities or services, establishing the rules for client-device interaction. Ideally, all such interfaces should be clearly documented in user manuals and accessible through a centralized, well-defined partition for optimal user experience and security transparency. However, the focus of this research is on hidden interfaces—those that are undocumented, untraceable, and often remain unknown to legitimate users and even security researchers. These hidden interfaces pose a significant threat by creating undisclosed access channels that can be exploited by malicious actors, leading to unauthorized access, data breaches, or device compromise.

The underlying mechanism for managing these interfaces typically involves handlers that process requests. A routing mechanism is responsible for passing incoming interface requests and directing data to the correct handlers. This redirection is based on routing tokens embedded within the request, which correspond to specific interfaces defined in a routing table. The routing table essentially maps these tokens to their respective handlers, dictating the flow of interaction.

Discovering these hidden web interfaces presents a substantial challenge for traditional bug-finding solutions. Static analysis struggles due to the lack of clear, consistent patterns for hidden interfaces within the firmware code. Without explicit definitions or documentation, it's difficult to identify code segments related to these hidden functionalities. Similarly, dynamic testing methods like fuzzing are largely ineffective because they cannot target unknown interfaces; if the interface path or parameters are unknown, fuzzers lack the necessary input space to explore. Taint analysis also faces difficulties, as defining appropriate sources or sinks related to these hidden, undocumented interfaces becomes an intractable problem. The core insight that underpins EagleEye is that while hidden, these interfaces are still dispatched in the same fundamental way as public ones, meaning their routing tokens and the context in which they appear often share similar code patterns. This shared pattern becomes the critical key to their discovery.

Key Findings

▶ Watch: Eagle Eye's intuition: focusing on routing tokens (2:40)

EagleEye's comprehensive evaluation yielded significant and concerning findings regarding the prevalence and security risks associated with hidden web interfaces in IoT devices. The research team tested 13 commercial devices from leading manufacturers, including Cisco, covering a diverse range of IoT device types.

The most striking discovery was the identification of a total of 79 hidden interfaces across these tested devices. This figure alone highlights the widespread nature of the problem, indicating that such interfaces are not isolated anomalies but a common occurrence in commercially available IoT products. Further analysis revealed a critical breakdown of these interfaces:

  • 27 interfaces were found to bypass authentication, meaning they could be accessed by an attacker without needing any credentials. This represents a severe security vulnerability, as it provides immediate, unauthorized access channels.
  • 52 interfaces were accessible after authentication, still posing a significant risk as they represent undocumented functionalities that could be exploited by an authenticated attacker or provide deeper access than intended.

Quantitatively, the findings are even more alarming:

  • Over 19% of the tested devices contained hidden interfaces.
  • Crucially, over 60% of the devices had unauthenticated hidden interfaces, underscoring the severe lack of security controls often present in these hidden pathways. The prevalence of authenticated hidden interfaces was approximately twice that of unauthenticated ones, indicating a broader issue of undocumented functionality within device firmware, regardless of access control.

To benchmark EagleEye's effectiveness, the researchers compared it against IoT-Scope, a state-of-the-art solution focusing on URL-based and unauthorized authenticated hidden interfaces. In this comparison, IoT-Scope managed to find only 3 hidden interfaces, while EagleEye successfully identified 79, demonstrating a vastly superior capability in discovering these elusive access points. EagleEye's average identification of 4.5 variable token fields and filtering out 2.0 irrelevant token fields per device highlights its precision in identifying relevant routing tokens.

Perhaps the most critical finding was the direct security impact of these hidden interfaces. By further analyzing the discovered interfaces, EagleEye's team uncovered a total of 29 unknown vulnerabilities, including critical backdoors, on these previously unseen access points. Of these, 7 vulnerabilities have already been assigned CVEs, validating their severity and novelty. The research presented three typical cases and causes of these vulnerabilities in the full paper, illustrating the concrete threats posed by these hidden pathways. The effectiveness of EagleEye's Automated Regular Expression Module (ARM), which learned varying patterns of routing tokens across devices, was also a key finding, achieving high accuracy with minimal human correction, often just one or two adjustments. This automation and adaptability are crucial for scalable vulnerability discovery.

Technical Deep Dive

▶ Watch: Leveraging ARM for routing token pattern learning (4:50)

EagleEye is structured as a sophisticated two-stage process: Intelligent Routing Analysis and Directed Blackbox Fuzzing. This combination allows it to systematically identify and exploit hidden web interfaces in IoT devices.

Stage 1: Intelligent Routing Analysis

The primary goal of the first stage is to intelligently extract the routing table from the device firmware. This stage leverages the crucial observation that both public and hidden interfaces within a device generally share a similar dispatching mechanism, implying that their routing tokens and contexts will exhibit common code patterns.

  1. Routing Token Identification: The process begins by analyzing public requests to identify potential routing tokens. Requests are decomposed into individual tokens based on their grammatical structure. By comparing tokens found in the same fields across multiple requests, EagleEye identifies variable tokens as likely candidates for routing tokens. To refine this, certain token types that are highly variable but not routing-related (e.g., timestamps, session IDs) are eliminated by analyzing their temporal characteristics. For multi-level tokens (e.g., /api/v1/users/{id}), requests are clustered by their primary routing tokens. If multiple requests share a common upper-level token, a partial order is established between the upper and lower routing tokens to effectively handle these hierarchical dependencies.
  1. Pattern Learning with ARM: With potential routing tokens identified, EagleEye employs an Automated Regular Expression Module (ARM) to learn the common patterns within the code context surrounding these tokens. The ARM is designed to analyze extracted code contexts and deduce the underlying program semantics. Two tailored prompts guide the ARM:
  • Semantic Understanding: The ARM analyzes the code surrounding known routing tokens to understand the program's logic and how these tokens are processed. This includes considering potential concealment mechanisms within control or data flow that might obscure hidden tokens.
  • Formatting Pattern Generation: To comprehensively extract the routing table and reduce false negatives, the ARM learns the specific formatting patterns of routing tokens. It then generates regular expressions based on these learned patterns, which can be used to scan the entire program for similar tokens, thereby discovering hidden ones.
  • For cases where a file path is used as a routing token (e.g., /etc/config.json), the local file system directory tree is incorporated into the searching space. This guides the ARM to learn the correct patterns for file-based routing and mitigates initial errors.
  1. Self-Correction Model: To enhance accuracy and progressively refine its understanding, EagleEye integrates a self-correction model. This model iteratively adjusts the ARM's learning process by using both positive and negative samples. A subset of public routing tokens is reserved for verification, while the remainder forms the corpus for the ARM to learn from. The ARM's output is continuously evaluated against this verification set to identify missed instances (false negatives) and incorrect instances (false positives). Through finite iterations, the ARM progressively refines its understanding of routing token patterns, achieving higher accuracy and mastering the intricate patterns specific to different devices.

Stage 2: Directed Blackbox Fuzzing

Once the routing table is extracted and refined through intelligent analysis, EagleEye moves to the second stage: Directed Blackbox Fuzzing. This stage aims to actively expose hidden interfaces by leveraging the learned routing information.

  1. Seed Generation: EagleEye uses public requests as templates and the newly extracted routing table as a comprehensive fuzzing dictionary. This approach ensures that the generated seeds are high-quality and relevant to the device's expected interaction patterns.
  1. Mutation Strategy: During fuzzing, EagleEye's core mutation strategy involves systematically mutating the field of the routing token based on the patterns identified in the routing table. This directed approach is far more efficient than blind fuzzing, as it focuses mutations on the most critical part of the request for interface discovery.
  1. Parameter Collection and Response Analysis: As fuzzing progresses, EagleEye actively collects parameters from device responses. These collected parameters are then used to create new, more sophisticated requests, continuously expanding the exploration space and triggering more interfaces. In blackbox testing, the device's response is paramount for determining the validity of a mutated request and indicating a potential hidden interface. EagleEye analyzes invalid responses, which often follow a general pattern despite minor variations. These typically include responses indicating unauthenticated or unauthorized access, or incorrect parameters. The system decomposes responses into discrete snippets and identifies those unique snippets that are exclusive to invalid responses. This allows EagleEye to reliably distinguish between a valid interaction with a hidden interface and an outright failed or irrelevant request, effectively filtering noise and focusing on legitimate discoveries. The continuous growth trend in discovered parameters and triggered interfaces, as shown by the blue line in the presentation's figures, reflects the effectiveness of EagleEye's mutation strategy in producing better seeds over time.

Demo / Proof of Concept

▶ Watch: Self-correction model for pattern refinement (6:00)

While the presentation transcript does not detail a live, interactive demonstration of EagleEye in action, the robust evaluation results serve as a compelling and undeniable proof of concept for its capabilities. The research team rigorously applied EagleEye to 13 commercial IoT devices from various leading manufacturers.

The successful identification of 79 hidden interfaces across these diverse devices, with a breakdown of 27 unauthenticated and 52 authenticated access points, unequivocally demonstrates EagleEye's effectiveness in real-world scenarios. Furthermore, the subsequent discovery of 29 unknown vulnerabilities, including critical backdoors, directly on these hidden interfaces, provides concrete evidence of the security risks they pose. The assignment of 7 CVEs to these newly found vulnerabilities by the broader security community further validates the severity and novelty of EagleEye's findings.

The talk alluded to presenting "three typical cases and for causes under the hidden interfaces" in the full paper, which would provide specific examples of how these vulnerabilities manifest and could be exploited. This detailed enumeration of actual vulnerabilities, rather than just theoretical possibilities, strongly validates EagleEye's practical utility as a security analysis tool. The quantitative comparison against IoT-Scope, where EagleEye found 79 interfaces compared to IoT-Scope's 3, also acts as a powerful demonstration of its superior performance and unique approach. Thus, while a live demo wasn't explicitly described in the transcript, the extensive and impactful results unequivocally prove EagleEye's efficacy as a groundbreaking solution for uncovering hidden web interfaces and their associated vulnerabilities in IoT devices.

Defensive Implications

▶ Watch: Comparison with IoT Scoop and automation benefits (9:00)

The findings from EagleEye's research carry significant implications for both IoT device manufacturers and security defenders. The pervasive nature of hidden web interfaces and the critical vulnerabilities they harbor necessitate a multi-faceted approach to enhance IoT security.

For IoT Manufacturers:

  • Embrace Secure-by-Design Principles: Manufacturers must fundamentally re-evaluate their development lifecycles to integrate security from the earliest stages. This includes a strict policy against undocumented or hidden functionalities. Every interface, regardless of its intended purpose (internal or external), should be explicitly defined, documented, and subject to rigorous security review.
  • Thorough Firmware Audits: Regular and comprehensive security audits of firmware are crucial. This should include specialized tools and methodologies, potentially inspired by EagleEye, to actively search for undocumented interfaces and ensure their absence or proper securing.
  • Implement Robust Access Controls: All interfaces, even those considered "internal" or "administrative," must be protected by strong authentication and authorization mechanisms. Unauthenticated access to any functionality, especially hidden ones, is an unacceptable risk. Multi-factor authentication should be considered for critical administrative interfaces.
  • Clear Documentation and Transparency: Manufacturers should strive for greater transparency, providing clear and complete documentation for all exposed interfaces. This not only aids legitimate users and administrators but also allows for better security assessments by third parties.
  • Continuous Fuzzing and Testing: Integrating advanced fuzzing techniques, similar to EagleEye's directed blackbox fuzzing, into their continuous integration/continuous deployment (CI/CD) pipelines can help proactively identify and remediate hidden interfaces before devices reach the market.

For Security Defenders and Users:

  • Patch Management: Promptly applying firmware updates and security patches released by manufacturers is paramount, as these often address known vulnerabilities, including those discovered in hidden interfaces.
  • Network Segmentation: Isolate IoT devices on dedicated network segments or VLANs. This limits the blast radius of a compromised IoT device and prevents attackers from easily pivoting to other critical network assets.
  • Traffic Monitoring and Anomaly Detection: Implement network monitoring solutions to detect unusual traffic patterns originating from or directed towards IoT devices. Unexpected requests to undocumented paths or unusual data exfiltration attempts could indicate the exploitation of a hidden interface.
  • Consider Internal Audits: Larger organizations with significant IoT deployments might consider conducting their own internal security audits, potentially employing sophisticated tools or services that can uncover hidden interfaces, mimicking the approach of EagleEye.
  • Awareness and Education: Users and administrators need to be educated about the risks of hidden interfaces and the importance of secure configuration practices for IoT devices.

In essence, EagleEye's research highlights a blind spot in current IoT security. Addressing this requires a concerted effort from both producers to eliminate these hidden doors and from consumers and defenders to secure their environments against the threats they pose.

Key Takeaways

  • Hidden web interfaces are a prevalent and significant, yet often overlooked, security threat in commercial IoT devices. They provide undocumented and untraceable access channels that can be exploited by attackers.
  • Traditional vulnerability discovery methods are largely ineffective against hidden interfaces due to the lack of clear patterns for static analysis and insufficient feedback for dynamic testing.
  • EagleEye is a novel, two-stage solution (Intelligent Routing Analysis + Directed Blackbox Fuzzing) that effectively discovers these hidden interfaces by learning routing patterns from public interfaces and then systematically mutating routing tokens.
  • The research uncovered a staggering 79 hidden interfaces across 13 commercial IoT devices, leading to 29 unknown vulnerabilities (including backdoors) and 7 assigned CVEs. A significant portion (over 60%) of devices had unauthenticated hidden interfaces.
  • EagleEye's Automated Regular Expression Module (ARM) and self-correction model are critical for its automation and high accuracy, enabling it to learn complex routing token patterns with minimal human intervention.
  • IoT manufacturers must prioritize secure-by-design principles, rigorously audit firmware for undocumented functionalities, and implement robust access controls for all interfaces. Defenders should focus on patch management, network segmentation, and anomaly detection to mitigate risks.

About the Speaker(s)

The research titled "EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing Analysis" was presented at the NDSS Symposium by Hangtian Liu. Liu delivered the presentation on behalf of the authors, who were unable to be on-site due to visa issues. The presentation covered their novel solution, EagleEye, and its significant findings regarding hidden web interfaces and associated vulnerabilities in IoT devices.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid academic research with a clear novel contribution: framing hidden IoT web interface discovery as a routing analysis problem rather than a fuzzing-everything-and-hoping problem. The numbers are credible and the comparison against IoT-Scope is honest — 79 vs. 3 interfaces found is a meaningful delta, not a cherry-picked benchmark. Not a paradigm-shifter, but this is real work done by people who clearly went into the firmware.

Heather Calloway (CISO) — WEAK

Technically credible research with real findings — 79 hidden interfaces, 29 vulnerabilities, 7 CVEs across commercial IoT devices — but the talk never bridges the gap between firmware analysis and the institutional decisions that actually determine whether this problem gets fixed. The defensive section reads like a generic security checklist, not a consequence-driven argument.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025