
Chimay-Red
Working POC of Mikrotik exploit from Vault 7 CIA Leaks

Working POC of Mikrotik exploit from Vault 7 CIA Leaks

Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

Statically compiled ARM binaries for debugging and runtime analysis

Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and…

Proof-of-concept exploit for CVE-2026-1668 in TP-Link switch firmware, delivering a MIPS payload that yields a root shell on vulnerable devices.

An open-source TPM device-attest-01 CA server

IoT firmware identification and extraction

Tool for reconstructing SPI flash images via logic analyzer captures

Python proof-of-concept scripts for the MikroTrick MikroTik RouterOS SSH takeover chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) for…

CVE-2026-86060 - CVE-2026-67279 - CVE-2026-67276 RouterOS SSH

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

Proof-of-concept demonstrating a microarchitectural data leak in Loongson LA464/LA664 processors via undefined upper bits of LASX vector registers,…

Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock.

A collection of vulnerabilities & exploits against modern GCS

Standalone proof of concept for CVE-2026-86547, a NULL pointer dereference in mrubyc op_enter() through 4.0.0.

Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept…

Firmware reverse engineering of the Philips PM5139 / PM5138A / PM5136 function generators: 8051 emulators used as measuring instruments, 35 sections…