
PoC
Publicly disclosed PoCs for IoT devices (IP cameras) focusing on authentication bypass, RCE, and stack overflow vulnerabilities.

Publicly disclosed PoCs for IoT devices (IP cameras) focusing on authentication bypass, RCE, and stack overflow vulnerabilities.

Collection of proof-of-concept exploits covering local and remote code execution, privilege escalation, web application flaws, and mobile/embedded…

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

Authenticated remote code execution exploit for Tp-Link Archer AX50 routers, leveraging backup file manipulation to inject commands and start a…

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

Webkit exploit that give arbitrary R/W on 6.XX PS4 firmwares

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Authenticated remote code execution exploit for CERIO routers (DT300N, DT100G, AMR-3204, WMR-200N) using vendor default credentials. Python PoC…

Proof-of-Concept exploits for D-Link DIR8xx routers

Proof-of-concept exploit for CVE-2023-35086, a format string vulnerability in ASUS router httpd service enabling remote code execution via crafted…

An implementation of CVE-2016-0974 for the Nintendo Wii.

Authenticated remote code execution exploit for TP-Link Archer C5 routers via malicious configuration file upload. Injects OS commands with root…

Proof-of-concept exploit for a buffer overflow vulnerability in ASUS RT-AX86U router firmware's httpd module, causing denial of service via crafted…

TP-Link TL-WR1043ND - Authenticated Remote Code Execution

PoC exploit chain for pre-authentication remote code execution on SonicWall SMA 100 appliances exploiting CVE-2023-44221 and CVE-2024-38475.

Documentation of CVE-2020-10558: a remote DoS vulnerability in Tesla Model S/3/X infotainment systems via crafted web pages, with technical analysis,…

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…