
nexmon
The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

Presented at Recon Montreal 2018

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

CVE-2024-46383

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

CVE-2024-44815

PoC for CVE-2020-11896 Treck TCP/IP stack and device asset investigation

Tools for reverse engineering and interacting with the PowerG radio protocol

Osqery extension HP BIOS WMI