
CVE-2026-75616
Proof-of-concept exploit for authenticated OS command injection in TP-Link Archer C20 v6 web management interface, executing root commands via BPA…

Proof-of-concept exploit for authenticated OS command injection in TP-Link Archer C20 v6 web management interface, executing root commands via BPA…

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

Python-based PoC exploit for CVE-2022-30024 enabling remote code execution on TP-Link WR841 v10 routers.

Proof-of-concept exploit for pre-authentication path traversal in Zephyr RTOS HTTP server static-fs handler, demonstrating directory traversal via…

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

PoC for three unauthenticated command injection vulnerabilities (CVE-2026-11450/1/2) in GL.iNet Beryl AX travel router firmware <=4.4.5, exploiting…

Proof-of-concept of vulnerability found in Totolink A720R router

CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE

SETROOTCERTIFICATE (write /etc/cert.pem.1) + APPLYAPP (RC_SERVICE execution). Refs: CVE-2025-2492, CVE-2024-12912, CVE-2025-59366; runZero;…

CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Proof-of-concept exploit for CVE-2025-1739 demonstrating authentication bypass via Base64-encoded Basic Auth token leakage on Trivision NC227WF IP…

Python port of the Linksys tmUnblock.cgi RCE exploit

Documentation of CVE-2020-10558: a remote DoS vulnerability in Tesla Model S/3/X infotainment systems via crafted web pages, with technical analysis,…

Proof-of-concept exploit for CVE-2025-67445: unauthenticated remote DoS via oversized HTTP POST request causing segmentation fault in TOTOLINK X5000R…

Collection of proof-of-concept exploits covering local and remote code execution, privilege escalation, web application flaws, and mobile/embedded…