Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-38698-and-CVE-2026-38699 — Technical details and publication about CVE-2026-38698 and CVE-2026-38699 | Kitploit
Tools/GitHubGitHub/vital-information-resource-under-siege/cve-2026-38698-and-cve-2026-38699
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationFuzzingPenetration TestingHardware SecurityBinary Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
vital-information-resource-under-siege/cve-2026-38698-and-cve-2026-38699

CVE-2026-38698-and-CVE-2026-38699

Technical details and publication about CVE-2026-38698 and CVE-2026-38699

View Repository
3 months agoNot yet reviewed

Research on Wyze Cam Pan v3

Slides

Reference

CVE-2026-38698

Attack Name

Heap Overflow on tutk_packet_alloc function in tutk_av_server

Additional Details

Afftected product

TUTK SDK v.3.1.10.0 through v.4.3.8.1

Affected Component

tutk_packet_Alloc function

Attack Vector

An authenticated attacker must send a crafted oversized AV packet derived from a decrypted UDP payload to port 32761.

Reference

Report

Video

poc_heap_overflow

POC

poc

CVE-2026-38699

Attack Name

OOB Read on 0x407 Handler

Additional Details

Afftected product

TUTK SDK v.3.1.10.0 through v.4.3.8.1

Affected Component

__Fill_ReadBuf function

Attack Vector

An local attacker must send a crafted UDP packet with an invalid payload offset.

Reference

Report

Video

poc_oob_read

POC

POC

Download Tool