
GhostESP
The open-source wireless research platform for ESP32.

The open-source wireless research platform for ESP32.

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and…

Predatory ESP32 Firmware

Flipper Zero firmware source code

Firmware repository for CatSniffer, a multi-protocol IoT security research board supporting BLE, Zigbee, Sub-1 GHz, and more, with version-specific…

Firmware for getting a power trace of the behavior of the bluetooth module on the ESP32 when the ESP32 is sent the undocumented hci bluetooth…

Simulated BLE peripheral exposing an unauthenticated GATT firmware-update characteristic; demonstrates critical CVE-2026-22017 device-takeover…

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

Firmware for converting consumer LoRa radios into KISS TNC modems with serial CLI, BLE packet sniffing, and APRS/AX.25 compatibility for packet radio…

Exploitation Framework for Embedded Devices

A security assessment of the Beat XP VEGA Smartwatch (Firmware RB303ATV006229) focused on Bluetooth Low Energy (BLE) connectivity revealed a design…

Reverse Engineering of the Shining App Mask

Proof-of-concept for CVE-2025-63895: Bluetooth Classic LMP buffer overflow exploitation in JXL 9-inch Android car infotainment systems, enabling…

Bluetooth 5 and 4.x LE sniffer for TI CC1352/CC26x2 hardware with support for extended advertising, all PHY modes, MAC/RSSI filtering, and PCAP…

Proof of concept IoT/Ham Radio mesh network with global routing over the internet

Bluetooth experimentation framework for Broadcom and Cypress chips.

A writeup and theoretical Proof-of-Concept for CVE-2019-19194

Active Bluetooth BR/EDR Sniffer/Injector as cheap as any ESP32 board can get. Works with Scapy ;-)