PwnScan

Project · IoT exposure · SFU CMPT 783

Finds every device on a network without agents, fingerprints the IoT ones, and ranks their CVEs by how likely they are to be exploited.

Three methods, one inventory

ARP, mDNS and SSDP each see devices the others miss. A host agent runs discovery on the LAN and seeds results back to the API; a two-pass port scan then enumerates and version-probes only what is open.

Severity is not risk

IoT devices are matched to NVD CVEs, then ranked by CVSS × EPSS × exposure. A critical CVE nobody exploits drops below a moderate one being exploited in the wild on an exposed camera.