
amradio
FPGA-based 12-channel AM radio broadcast system with formal verification of a hardware watchdog for fail-safe emergency alert transmission in…

FPGA-based 12-channel AM radio broadcast system with formal verification of a hardware watchdog for fail-safe emergency alert transmission in…

Tools for analyzing Canon Pixma printer firmware

CVE-2017-5721 Proof-of-Concept

Z2A-BlackLotus Challenge stage 2 bootkit-rootkit analysis

CVE-2021-3707 , CVE-2021-3708

Tools used for decrypting Canon printers firmwares


wpa3 functionality for the wifi chip in a 2014 macbook pro

An implementation of baton drop (CVE-2022-21894) for armv7 (MSM8960)

BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748

Translated strings for World Conqueror 4 (RU)

Firmware extractor for CH55x microprocessors

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

Ghidra loader for the MediaTek md1img modem firmware image format

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)

Educational Python simulation demonstrating ECDSA nonce reuse in IoT firmware signing, showing how an attacker can recover private keys from two…