
CVE-2026-43499_HW-CLT-AL01
Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)

This is a collection of Unisoc BootROMs i've dumped from various Unisoc chipsets via CVE-2022-38694

Reverse engineering the TI AM3358 boot ROM

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…




Enable Microsoft PDB support in Ghidra without installing Visual Studio

A low pin count sniffer for ICEStick - targeting TPM chips

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.

Detecting vulnerabilities like CVE-2024-0762, particularly in UEFI firmware, is quite challenging due to the low-level nature

KERUI K259 5MP Wi-Fi (Tuya Smart Security Camera) contains a code execution vulnerability


CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

CVE-2021-21735 write-up: ZTE ZXHN H168N V3.5 wizard-page information leak, firmware routing flaw, and the path from exposed PPPoE/WLAN data to full…