
ghostlock-cve-2026-43499
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

Authenticated Remote Code Execution vulnerability in Xerox WorkCentre printers via the Network Troubleshooting Log feature.

Complete firmware vulnerability analysis for CVE-2020-9373 Netgear R6400 UPnP stack overflow, including unpacking, reverse engineering, static…

Rediscovered CVE-2020-25279, a critical vulnerability in the Shannon baseband used in Samsung Exynos chipsets

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

Information and PoC about the ENLBufferPwn vulnerability

Software-only proof of concept for CVE-2025-52464 in Meshtastic Direct Messages

CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.


A collection of my public security advisories.


Privilege escalation vulnerability on ASKEY routers

Read out-of-bounds PoC for miniupnpd <= v2.1

IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note…


Proof-of-concept exploit for CVE-2026-52504 targeting Exein Pulsar, with detailed vulnerability description and exploitation methodology.