
iodine
Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Proof of Concept for the CVE-2026-22226

Proof-of-concept exploit for CVE-2024-3400, a Palo Alto OS command injection in GlobalProtect VPN. Demonstrates file creation and outbound command…

Pulse Secure VPN mitm Research - CVE-2020-8241, CVE-2020-8239

Proof-of-concept exploit for CVE-2022-30525, a remote command injection vulnerability in Zyxel firewalls, with netcat reverse shell and DNS log…

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

Zyxel 防火墙未经身份验证的远程命令注入

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…

CVE-2020-8250: Privilege Escalation via Command Injection in Pulse Secure VPN Linux Client

TP-Link ER7206 Omada Gigabit VPN Router uhttpd freeStrategy Command injection Vulnerability

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…