Finite State assessment of firmwares
Just read the 2-page key findings (and then go hide under a blanket, shivering).

@zacchiro brrrrrrrrrrrr and they even dare to accuse opensource

@efraim @zacchiro

On dozens of occasions, Huawei engineers disguised known unsafe functions (such as memcpy) as the “safe” version (memcpy_s) by creating wrapper functions with the “safe” name but none of the safety checks. This leads to thousands of vulnerable conditions in their code.


