IoT vulnerabilities as a persistent exploitation risk: a longitudinal, statistical, and predictive analysis of CVE disclosures (2015–2025)

Purpose This study aims to investigate cybersecurity risks associated with the rapid expansion of Internet of Things (IoT) deployments, with a focus on vulnerability trends and the relationship between common vulnerabilities and exposures (CVE) disclosures and real-world exploitation. Design/methodology/approach A longitudinal analysis of data from the National Vulnerability Database (NVD) was conducted covering the period from 2015 to 2025. The study identified IoT-related CVEs and applied statistical modeling alongside supervised machine learning techniques, including ensemble approaches such as CatBoost, to predict exploitability and classify vulnerability severity. Additional validation was achieved through integration of threat intelligence sources, including CISA Known Exploited Vulnerabilities (KEV) catalog and external exploit repositories. Findings The analysis identified 44,569 IoT-related CVEs, representing approximately 18% of all disclosures during the study period. While overall CVE exploitation rates remained below 0.2% annually, IoT vulnerabilities were exploited at rates five to ten times higher, with notable peaks in 2020 and 2023. IoT classification emerged as the strongest predictor of exploitation, exceeding the influence of CVSS severity tiers. Machine learning models demonstrated strong performance, with CatBoost achieving ROC–AUC values of approximately 0.91, while severity classification models achieved macro-averaged F1 scores above 0.60 and accuracy exceeding 0.74. Research limitations/implications This study relied primarily on publicly available vulnerability repositories, including the NVD and CISA KEV catalog, which may contain incomplete or inconsistently classified records. IoT vulnerability identification was based on keyword- and CPE-driven filtering approaches that may not capture all embedded or hybrid devices. In addition, confirmed exploitation data likely underestimate real-world attack activity because many exploitation events remain undisclosed. Despite these limitations, the study contributes a scalable framework integrating longitudinal vulnerability analytics, threat intelligence correlation and machine learning-based exploitability prediction for IoT cybersecurity research. Practical implications The findings support the integration of machine learning-assisted vulnerability prioritization and threat intelligence correlation into IoT cybersecurity risk management workflows, enabling organizations to more effectively identify high-risk vulnerabilities, improve remediation prioritization, optimize resource allocation and strengthen overall cybersecurity resilience across interconnected environments. Social implications By demonstrating that IoT vulnerabilities exhibit consistently elevated observed exploitation likelihood relative to non-IoT vulnerabilities, this study contributes to broader awareness of systemic cybersecurity risks associated with interconnected devices and supports efforts to improve IoT security practices, coordinated vulnerability management and critical infrastructure protection across industry and society. Originality/value This study provides empirical evidence of the structural exploitability of IoT ecosystems and demonstrates the effectiveness of integrating statistical analysis, machine learning and threat intelligence feeds to improve vulnerability assessment and prioritization.

Authors

Institutions

Publication Details

Journal
Information and Computer Security
Published
2026-09-15
DOI
https://doi.org/10.1108/ics-05-2026-0282
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

IoT vulnerabilities as a persistent exploitation risk: a longitudinal, statistical, and predictive analysis of CVE disclosures (2015–2025)

Stephen Mujeye, Xing Liu, Pasan Edirisinghe
Information and Computer Security
Information and Cyber Security
article

IoT vulnerabilities as a persistent exploitation risk: a longitudinal, statistical, and predictive analysis of CVE disclosures (2015–2025)

Stephen Mujeye, Xing Liu, Pasan Edirisinghe
article en

Abstract

Purpose This study aims to investigate cybersecurity risks associated with the rapid expansion of Internet of Things (IoT) deployments, with a focus on vulnerability trends and the relationship between common vulnerabilities and exposures (CVE) disclosures and real-world exploitation. Design/methodology/approach A longitudinal analysis of data from the National Vulnerability Database (NVD) was conducted covering the period from 2015 to 2025. The study identified IoT-related CVEs and applied statistical modeling alongside supervised machine learning techniques, including ensemble approaches such as CatBoost, to predict exploitability and classify vulnerability severity. Additional validation was achieved through integration of threat intelligence sources, including CISA Known Exploited Vulnerabilities (KEV) catalog and external exploit repositories. Findings The analysis identified 44,569 IoT-related CVEs, representing approximately 18% of all disclosures during the study period. While overall CVE exploitation rates remained below 0.2% annually, IoT vulnerabilities were exploited at rates five to ten times higher, with notable peaks in 2020 and 2023. IoT classification emerged as the strongest predictor of exploitation, exceeding the influence of CVSS severity tiers. Machine learning models demonstrated strong performance, with CatBoost achieving ROC–AUC values of approximately 0.91, while severity classification models achieved macro-averaged F1 scores above 0.60 and accuracy exceeding 0.74. Research limitations/implications This study relied primarily on publicly available vulnerability repositories, including the NVD and CISA KEV catalog, which may contain incomplete or inconsistently classified records. IoT vulnerability identification was based on keyword- and CPE-driven filtering approaches that may not capture all embedded or hybrid devices. In addition, confirmed exploitation data likely underestimate real-world attack activity because many exploitation events remain undisclosed. Despite these limitations, the study contributes a scalable framework integrating longitudinal vulnerability analytics, threat intelligence correlation and machine learning-based exploitability prediction for IoT cybersecurity research. Practical implications The findings support the integration of machine learning-assisted vulnerability prioritization and threat intelligence correlation into IoT cybersecurity risk management workflows, enabling organizations to more effectively identify high-risk vulnerabilities, improve remediation prioritization, optimize resource allocation and strengthen overall cybersecurity resilience across interconnected environments. Social implications By demonstrating that IoT vulnerabilities exhibit consistently elevated observed exploitation likelihood relative to non-IoT vulnerabilities, this study contributes to broader awareness of systemic cybersecurity risks associated with interconnected devices and supports efforts to improve IoT security practices, coordinated vulnerability management and critical infrastructure protection across industry and society. Originality/value This study provides empirical evidence of the structural exploitability of IoT ecosystems and demonstrates the effectiveness of integrating statistical analysis, machine learning and threat intelligence feeds to improve vulnerability assessment and prioritization.

Information and Computer Security
Sam Houston State University (US)
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.