
Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.
This repository serves as a centralized public archive for my independent vulnerability research, hardware audits, and Coordinated Vulnerability Disclosures (CVD).
All proof-of-concept scripts, firmware extractions, and hardware teardowns are published here strictly for educational purposes and defensive security research. Disclosures are made following standard industry timelines (CERT/CC 90-day embargoes or 45-day unresponsive vendor exceptions).
| Date | Vendor / Device | Vulnerability Type | Status | Link |
|---|---|---|---|---|
| April 2026 | GNCC GP5 (T23) | Hardware to Cloud / Persistent Root | Unpatched / 6 CVE | View Report |
| July 2026 | Kasa EC71 | Hardcoded RSA, MD5 User Creds, Precise GPS Disclosure | Patched / 2 CVE | View Report |
My research primarily focuses on bridging the gap between localized physical hardware flaws and systemic infrastructure risk. Methodologies include: