
iodine
Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Proof-of-concept exploit for CVE-2024-3400, a Palo Alto OS command injection in GlobalProtect VPN. Demonstrates file creation and outbound command…

Pulse Secure VPN mitm Research - CVE-2020-8241, CVE-2020-8239

TP-Link ER7206 Omada Gigabit VPN Router uhttpd freeStrategy Command injection Vulnerability

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

CVE-2020-8250: Privilege Escalation via Command Injection in Pulse Secure VPN Linux Client

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

Zyxel 防火墙未经身份验证的远程命令注入

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

Proof-of-concept exploit for CVE-2022-30525, a remote command injection vulnerability in Zyxel firewalls, with netcat reverse shell and DNS log…

Proof of Concept for the CVE-2026-22226