
rosemary
Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor…

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

CVE-2025-57174 Unauthenticated Remote Command Execution

A native backdoor module for Microsoft IIS (Internet Information Services)

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

Aggressor Script to launch IE driveby for CVE-2018-15982.

Detailed technical analysis and proof-of-concept exploit for CVE-2023-20209, a post-authentication remote code execution vulnerability in Cisco…

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS

TP-Link Archer AXE75 Authenticated Command Injection

Proof-of-concept exploit for CVE-2022-31898, a command injection vulnerability in GL-iNet routers (firmware < 3.215). Provides reverse shell via…

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

Proof-of-concept exploit for CVE-2024-7120 command injection vulnerability in RAISECOM gateway devices. Provides exploitation details, affected…