Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
zyxel-wax650s-research-notebook-public — Wiki-style research notebook for Zyxel WAX650S firmware emulation and vulnerability analysis | Kitploit
Tools/GitHubGitHub/minanagehsalalma/zyxel-wax650s-research-notebook-public
Embedded Systems SecurityVulnerability AnalysisReverse EngineeringWeb SecurityFirmware Analysis
GitHubminanagehsalalma/zyxel-wax650s-research-notebook-public

zyxel-wax650s-research-notebook-public

Wiki-style research notebook for Zyxel WAX650S firmware emulation and vulnerability analysis

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
4 months agoNot yet reviewed

Zyxel WAX650S Research Notebook

Public-safe research notebook for Zyxel WAX650S firmware V7.10(ABRM.4)C0.

This repo is written as a story-format wiki for researchers and future LLM-assisted follow-up work. It captures how the lab was brought up, which findings were confirmed, which chains failed, and where the evidence boundaries sit.

Target

  • Device: Zyxel WAX650S
  • Firmware: V7.10(ABRM.4)C0
  • Firmware SHA-256: e0a93db912c0b7203e0eb899f07ddef99b62a82a27352477c0f85d761576b1e0
  • Architecture: AArch64 userland
  • Main web stack: Zyxel lighttpd, mod_auth_zyxel.so, CGI handlers, zyshd, UAM sockets

How To Read This

Start with Home, then read the numbered chapters under docs. The notebook intentionally separates:

  • confirmed findings from candidates
  • static evidence from dynamic evidence
  • synthetic lab state from device-faithful runtime behavior
  • exploitability from useful defensive research boundaries

Contents

  • Story Overview
  • Target, Firmware, And Extraction
  • Emulation Bring-Up
  • Web Auth And Session Model
  • Cookie Parser Mismatch
  • PKCS#12 Export Command Injection
  • Reversible Password Research
  • Captive Portal Runtime
  • Captive Portal Open Redirect Family
  • Negative Results And Dead Ends
  • Disclosure Packaging
  • LLM-Assisted Methodology
  • Artifact Map
  • Timeline And Checkpoints
  • Finding Matrix

What Is Not In This Repo

This repo deliberately excludes raw firmware images, extracted rootfs trees, runroot, large traces, live process state, private disclosure correspondence, and bulk logs. The goal is a durable research reference, not a forensic dump.

Curated evidence is under artifacts. Selected helper scripts are under tools-reference.

Public Release Status

This tree is prepared as a clean-history public snapshot. It should be published only after the relevant coordinated disclosure window allows release. The full private research archive is intentionally separate.

Download Tool