Published December 13, 2025 | Version v1

Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT Firmware

  • 1. ROR icon Institute of Information Engineering
  • 2. ROR icon University of Chinese Academy of Sciences
  • 3. Ant Group & Tsinghua University
  • 4. University of Waterloo

Description

Bond

  • Artifact for USENIX Security '26 Submission

  • 《Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT Firmware》

Overview

Bond is a directed fuzzing framework for the automated validation of taint analysis reports. Based on the (source, sink, call traces) information contained in the reports, Bond performs entry point identification, constraint analysis, and black-box validation. To use Bond, some environment configuration is required, after which the tool can be executed from the command line. The inputs are firmware binaries together with taint analysis reports, and the expected output is a proof of concept. During execution, Bond also generates intermediate output files, such as path constraint analysis results and entry point identification results.

Dependencies

  • Python 3.7

  • Java 8 (1.8.0_202)

  • npm 10.8.2

  • Python packages (see requirements.txt)

  • IDA Pro 7.5

Configuration

Since we have modified the underlying mutation logic of BooFuzz, and our constraint analysis is built on EmTaint, which requires changes to the core code of Angr, you will need to replace several library files. We have provided the necessary patched libraries and their relative paths under the third_party directory.

run_para.py: Contains device-specific configurations, such as login credentials and IP addresses.

dataflow.conf: Contains directory configurations, for example, you need to specify the path to your IDA Pro engine here.

Usage

  1. Setup the testing environment;

  2. Run Bond in the following way:

    python Bond.py -f "DIR816_1.10CNB05" -b "goahead"
  3. Check the output and the result folder for results.

Important Files and Directories

Path Description
Bond_result/firmware_complete/ Full dataset of processed firmware-(Dataset)
Bond_result/firmware_final/ Final dataset used in experiments-(Dataset)
Bond_result/static_report/ Aligned Taint Analysis Reports from Four Tools-(Dataset)
Bond_result/action_find/ Entry Point Identification Results-(Output)
Bond_result/custom_analysis/ Path Constraint Analysis Results-(Output)
fuzz_log/fuzz_sent_log.txt Proof of Concept (PoC)-(Output)

CVE Reports

This dataset is used for validating known vulnerabilities. It is located at:

Bond_result\custom_analysis\A3002R_1.1.1

Here, A3002R_1.1.1 represents the firmware model. For example, within this folder you will find:

A3002R_1.1.1_boa_CVE_reports.json

This JSON file already contains the annotated vulnerability points. You can directly feed it into Bond to perform validation.

ID Source->Sink
R8500  
PSV-2020-0259 25968->251a8
R7000P  
PSV-2021-0342 95110->95174
PSV-2022-0201 94E74->94E88
CVE-2022-44193 49698->4983C
CNVD-2022-70682 79BE4->79C4C
PSV-2020-0310 CFE74->CFEC0
PSV-2020-0311 CFF0C->CFF48
PSV-2020-0312 CF590->CF728
PSV-2020-0314 9C884->913B4
XR300  
PSV-2022-0004 C6990->C69A0
PSV-2022-0140 2589C->2511C
PSV-2022-0171 C683C->C68E4
EX6120  
CVE-2025-4139 46EFF8->46F0C0
E1700  
CVE-2024-22544 425C3C->425D08
RE6500  
CVE-2020-35713 424764->426838
DIR816  
CVE-2018-17065 457E54->4580EC
CVE-2018-17068 45AD00->45AEE8
CVE-2022-29321 425974->425BC4
CVE-2022-37123 456764->456834
CVE-2022-37134 42F0B0->42F1B8
CVE-2022-37125 4572D0->457420
CVE-2022-43003 442F28->442F5C
CVE-2023-43237 42D8F4->42DA18
CVE-2023-43240 44DF0C->445FA0
CVE-2024-24321 42E278->42E468
CVE-2025-29743 42AA70->429104
DIR619L  
CVE-2023-43862 460AD0->460B24
CVE-2024-9908 47179C->47184C
CVE-2024-9909 446368->4463D4
CVE-2024-9566 453ABC->453CC8
CVE-2024-33774 46676C->46686C
CVE-2025-4448 45E724->45EA3C
CVE-2025-4451 451C30->451ED8
DCS932L  
CVE-2016-11021 431048->431080
CVE-2019-10999 436494->436470
A3002R  
CVE-2022-40110 41A440->41A52C
CVE-2025-25610 45931C->459338
CVE-2025-45861 456950->45695C
CVE-2025-45865 4569D8->4569E4
CA300-POE  
CVE-2023-24144 40286c->402b2c
CVE-2023-24148 401354->401658
AX3  
CVE-2022-24145 35DE8->35EB8
CVE-2022-24146 5EFCC->4D2AC
CVE-2022-24149 39E6C->39F3C
CVE-2022-24157 443BC->4180C
CVE-2022-24158 539E8->53B14
CVE-2022-24159 48DF4->48E64
CVE-2022-24162 47354->473D8
CVE-2022-24163 57328->57390
O3V2  
CVE-2024-7151 467354->467844
CVE-2024-7152 473D24->4740D0
CVE-2024-34338 476510->475980
TL-WR841N  
CVE-2022-30024 455C40->47A274
CVE-2025-25898 46EA68->46EAB0
F9K1122  
ZDI-15-348 45585C->4558EC
ZDI-15-350 44980C->449850
ZDI-15-351 42ECB8->42ED58
CX2L  
CVE-2023-31528 4383E4->438318
CVE-2023-31529 42B1A0->42B248
CVE-2024-45880 43C864->402D80

Dataset

This artifact includes two datasets, comprising a total of 19 real-world firmware images used to evaluate Bond. Note that these datasets are already included in the code artifact, and no additional action is required.

ID Vendor Model Version(1-day/0-day) Type
1 Netgear R8500 /1.0.2.160 WiFi Router
2 Netgear R7000P 1.3.0.8,1.3.1.64/1.3.3.154 WiFi Router
3 Netgear XR300 1.0.3.72/1.0.3.78 WiFi Router
4 Netgear WNDR4500 /1.0.1.46 WiFi Router
5 Netgear EX6120 1.0.0.68/1.0.0.70 Range Extender
6 Netgear D6400 /1.0.0.114 DSL Modem
7 Linksys E1700 1.0.0.4.003/1.0.0.4.003 WiFi Router
8 Linksys RE6500 1.0.010.001/1.0.013.001 Range Extender
9 D-Link DIR816 1.10CNB03/1.10CNB05 WiFi Router
10 D-Link DIR619L 2.06B01/2.06B01 WiFi Router
11 D-Link DNS320L /1.11 Network Attached Storage
12 D-Link DCS932L 1.00/2.18.01 IP Camera
13 TOTOLink A3002R V1.1.1/V1.1.1 WiFi Router
14 TOTOLink CA300-PoE V6.2c.884/V6.2c.884 Wireless Access Point
15 Tenda AX3 V16.03.12.10/V16.03.12.10 WiFi Router
16 Tenda O3V2 1.0.0.12/1.0.0.12 Outdoor Wireless Bridge
17 TP-Link TL-WR841N V11_160325/V11_160325 WiFi Router
18 Belkin F9K1122 1.00.23/1.00.33 Range Extender
19 Motorola CX2L 1.0.1/1.0.1 WiFi Router

Files

Files (528.3 MB)

Name Size
md5:02460423468cfbac5ef243a8ec665916
528.3 MB Download