This study aims to investigate cybersecurity risks associated with the rapid expansion of Internet of Things (IoT) deployments, with a focus on vulnerability trends and the relationship between common vulnerabilities and exposures (CVE) disclosures and real-world exploitation.
A longitudinal analysis of data from the National Vulnerability Database (NVD) was conducted covering the period from 2015 to 2025. The study identified IoT-related CVEs and applied statistical modeling alongside supervised machine learning techniques, including ensemble approaches such as CatBoost, to predict exploitability and classify vulnerability severity. Additional validation was achieved through integration of threat intelligence sources, including CISA Known Exploited Vulnerabilities (KEV) catalog and external exploit repositories.
The analysis identified 44,569 IoT-related CVEs, representing approximately 18% of all disclosures during the study period. While overall CVE exploitation rates remained below 0.2% annually, IoT vulnerabilities were exploited at rates five to ten times higher, with notable peaks in 2020 and 2023. IoT classification emerged as the strongest predictor of exploitation, exceeding the influence of CVSS severity tiers. Machine learning models demonstrated strong performance, with CatBoost achieving ROC–AUC values of approximately 0.91, while severity classification models achieved macro-averaged F1 scores above 0.60 and accuracy exceeding 0.74.
This study relied primarily on publicly available vulnerability repositories, including the NVD and CISA KEV catalog, which may contain incomplete or inconsistently classified records. IoT vulnerability identification was based on keyword- and CPE-driven filtering approaches that may not capture all embedded or hybrid devices. In addition, confirmed exploitation data likely underestimate real-world attack activity because many exploitation events remain undisclosed. Despite these limitations, the study contributes a scalable framework integrating longitudinal vulnerability analytics, threat intelligence correlation and machine learning-based exploitability prediction for IoT cybersecurity research.
The findings support the integration of machine learning-assisted vulnerability prioritization and threat intelligence correlation into IoT cybersecurity risk management workflows, enabling organizations to more effectively identify high-risk vulnerabilities, improve remediation prioritization, optimize resource allocation and strengthen overall cybersecurity resilience across interconnected environments.
By demonstrating that IoT vulnerabilities exhibit consistently elevated observed exploitation likelihood relative to non-IoT vulnerabilities, this study contributes to broader awareness of systemic cybersecurity risks associated with interconnected devices and supports efforts to improve IoT security practices, coordinated vulnerability management and critical infrastructure protection across industry and society.
This study provides empirical evidence of the structural exploitability of IoT ecosystems and demonstrates the effectiveness of integrating statistical analysis, machine learning and threat intelligence feeds to improve vulnerability assessment and prioritization.
